twilio / twilio-node

Node.js helper library
MIT License
1.37k stars 497 forks source link

jsonwebtoken Use of a Broken or Risky Cryptographic Algorithm #891

Closed skt1598 closed 1 year ago

skt1598 commented 1 year ago

Introduced through: twilio@3.84.1 › jsonwebtoken@8.5.1

Affected versions of this package are vulnerable to Use of a Broken or Risky Cryptographic Algorithm such that the library can be misconfigured to use legacy, insecure key types for signature verification. For example, DSA keys could be used with the RS256 algorithm. Ref: https://security.snyk.io/vuln/SNYK-JS-JSONWEBTOKEN-3180026

isha689 commented 1 year ago

Duplicate Issue https://github.com/twilio/twilio-node/issues/846 We have updated our twilio-node v4 release candidate to v9