Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update node-jsonwebtoken deps to fix a critical vulnerability #3

Merged

Conversation

lushc
Copy link

@lushc lushc commented Apr 1, 2015

Write-up of the vulnerability in question: https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries/

This library is a few major versions behind so I'm a little paranoid but the tests still pass (after one fix, details in commit). I've also tested this branch on my own project and I'm still signing and authorising valid tokens.

pbuyle added a commit that referenced this pull request Apr 1, 2015
Update node-jsonwebtoken deps to fix a critical vulnerability
@pbuyle pbuyle merged commit b55a641 into FloeDesignTechnologies:master Apr 1, 2015
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants