Open KsenyaJSN opened 1 year ago
Vulnerable Dependency Information:
Package Name: jsonwebtoken Vulnerable Version: 9.0.0 Dependency with ReDoS Vulnerability: semver@7.3.8 Vulnerability Severity: High
https://security.snyk.io/package/npm/semver
Fixed in jsonwebtoken v.9.0.2 (https://github.com/auth0/node-jsonwebtoken/issues/921)
Hi @mikenicholson This is an important vulnerability. This library should be updated quickly. I should be very easy to upgrade since v9.0.2 is a patch version and you are already using 9.0.0 on master.
Thanks
Vulnerable Dependency Information:
Package Name: jsonwebtoken Vulnerable Version: 9.0.0 Dependency with ReDoS Vulnerability: semver@7.3.8 Vulnerability Severity: High
https://security.snyk.io/package/npm/semver
Fixed in jsonwebtoken v.9.0.2 (https://github.com/auth0/node-jsonwebtoken/issues/921)