Описание
Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| golang-github-openpubkey-openpubkey | fixed | 0.18.0-1 | package | |
| golang-github-openpubkey-openpubkey | no-dsa | trixie | package |
Примечания
https://github.com/openpubkey/openpubkey/security/advisories/GHSA-537f-gxgm-3jjq
Связанные уязвимости
CVSS3: 9.8
ubuntu
9 месяцев назад
Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.
CVSS3: 9.8
nvd
9 месяцев назад
Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.