manfredsteyer / angular-oauth2-oidc

Support for OAuth 2 and OpenId Connect (OIDC) in Angular.
MIT License
1.86k stars 681 forks source link

chore: Update jsrsasign due to CVE-2024-21484 Marvin attack of RSA and RSAOAEP decryption #1393

Closed BSekula closed 3 months ago

BSekula commented 5 months ago

Fix for https://github.com/manfredsteyer/angular-oauth2-oidc/issues/1391

Updating jsrsasign version to 11.0.0

rutalreja-deloitte commented 4 months ago

Can we merge this please, this is a critical vulnerability

BSekula commented 4 months ago

I do not have power to merge it.

@manfredsteyer could you please take a look?

rutalreja-deloitte commented 4 months ago

@manfredsteyer is there any blocker to merge this?

zhenli-ong commented 4 months ago

@manfredsteyer please help to complete the merge please

loona-rvr commented 4 months ago

up please @manfredsteyer @DenysVuika

diogogasparr commented 4 months ago

up @manfredsteyer @DenysVuika

loona-rvr commented 4 months ago

up again

leogouveia commented 3 months ago

@manfredsteyer @DenysVuika Any news about this PR?

jjbravo commented 3 months ago

hi @manfredsteyer , please, helpme with this change.

robke007 commented 3 months ago

@manfredsteyer, please make this a priority as it is critical vulnerability. Thanks!!