Количество 15
Количество 15
CVE-2024-51744
golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way they should be. Especially, if a token is both expired and invalid, the errors returned by `ParseWithClaims` return both error codes. If users only check for the `jwt.ErrTokenExpired ` using `error.Is`, they will ignore the embedded `jwt.ErrTokenSignatureInvalid` and thus potentially accept invalid tokens. A fix has been back-ported with the error handling logic from the `v5` branch to the `v4` branch. In this logic, the `ParseWithClaims` function will immediately return in "dangerous" situations (e.g., an invalid signature), limiting the combined errors only to situations where the signature is valid, but further validation failed (e.g., if the signature is valid, but is expired AND has the wrong audience). This fix is part of the 4.5.1 release. We are aware that this changes the behav...
CVE-2024-51744
golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way they should be. Especially, if a token is both expired and invalid, the errors returned by `ParseWithClaims` return both error codes. If users only check for the `jwt.ErrTokenExpired ` using `error.Is`, they will ignore the embedded `jwt.ErrTokenSignatureInvalid` and thus potentially accept invalid tokens. A fix has been back-ported with the error handling logic from the `v5` branch to the `v4` branch. In this logic, the `ParseWithClaims` function will immediately return in "dangerous" situations (e.g., an invalid signature), limiting the combined errors only to situations where the signature is valid, but further validation failed (e.g., if the signature is valid, but is expired AND has the wrong audience). This fix is part of the 4.5.1 release. We are aware that this changes the behav...
CVE-2024-51744
golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way they should be. Especially, if a token is both expired and invalid, the errors returned by `ParseWithClaims` return both error codes. If users only check for the `jwt.ErrTokenExpired ` using `error.Is`, they will ignore the embedded `jwt.ErrTokenSignatureInvalid` and thus potentially accept invalid tokens. A fix has been back-ported with the error handling logic from the `v5` branch to the `v4` branch. In this logic, the `ParseWithClaims` function will immediately return in "dangerous" situations (e.g., an invalid signature), limiting the combined errors only to situations where the signature is valid, but further validation failed (e.g., if the signature is valid, but is expired AND has the wrong audience). This fix is part of the 4.5.1 release. We are aware that this changes the behaviou
CVE-2024-51744
Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt
CVE-2024-51744
golang-jwt is a Go implementation of JSON Web Tokens. Unclear document ...
openSUSE-SU-2025:0131-1
Security update for coredns
SUSE-SU-2025:0546-1
Security update golang-github-prometheus-prometheus
GHSA-29wx-vh33-7x7r
Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations
openSUSE-SU-2026:20099-1
Security update for coredns
SUSE-SU-2025:1333-1
Security update for cosign
SUSE-SU-2025:0525-1
Security update for SUSE Manager Client Tools
openSUSE-SU-2026:20620-1
Security update for rclone
openSUSE-SU-2025:20117-1
Security update for trivy
openSUSE-SU-2026:20798-1
Security update for trivy
openSUSE-SU-2026:20654-1
Security update for grafana
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-51744 golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way they should be. Especially, if a token is both expired and invalid, the errors returned by `ParseWithClaims` return both error codes. If users only check for the `jwt.ErrTokenExpired ` using `error.Is`, they will ignore the embedded `jwt.ErrTokenSignatureInvalid` and thus potentially accept invalid tokens. A fix has been back-ported with the error handling logic from the `v5` branch to the `v4` branch. In this logic, the `ParseWithClaims` function will immediately return in "dangerous" situations (e.g., an invalid signature), limiting the combined errors only to situations where the signature is valid, but further validation failed (e.g., if the signature is valid, but is expired AND has the wrong audience). This fix is part of the 4.5.1 release. We are aware that this changes the behav... | CVSS3: 3.1 | 1% Низкий | почти 2 года назад | |
CVE-2024-51744 golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way they should be. Especially, if a token is both expired and invalid, the errors returned by `ParseWithClaims` return both error codes. If users only check for the `jwt.ErrTokenExpired ` using `error.Is`, they will ignore the embedded `jwt.ErrTokenSignatureInvalid` and thus potentially accept invalid tokens. A fix has been back-ported with the error handling logic from the `v5` branch to the `v4` branch. In this logic, the `ParseWithClaims` function will immediately return in "dangerous" situations (e.g., an invalid signature), limiting the combined errors only to situations where the signature is valid, but further validation failed (e.g., if the signature is valid, but is expired AND has the wrong audience). This fix is part of the 4.5.1 release. We are aware that this changes the behav... | CVSS3: 3.1 | 1% Низкий | почти 2 года назад | |
CVE-2024-51744 golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way they should be. Especially, if a token is both expired and invalid, the errors returned by `ParseWithClaims` return both error codes. If users only check for the `jwt.ErrTokenExpired ` using `error.Is`, they will ignore the embedded `jwt.ErrTokenSignatureInvalid` and thus potentially accept invalid tokens. A fix has been back-ported with the error handling logic from the `v5` branch to the `v4` branch. In this logic, the `ParseWithClaims` function will immediately return in "dangerous" situations (e.g., an invalid signature), limiting the combined errors only to situations where the signature is valid, but further validation failed (e.g., if the signature is valid, but is expired AND has the wrong audience). This fix is part of the 4.5.1 release. We are aware that this changes the behaviou | CVSS3: 3.1 | 1% Низкий | почти 2 года назад | |
CVE-2024-51744 Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt | CVSS3: 3.1 | 1% Низкий | больше 1 года назад | |
CVE-2024-51744 golang-jwt is a Go implementation of JSON Web Tokens. Unclear document ... | CVSS3: 3.1 | 1% Низкий | почти 2 года назад | |
openSUSE-SU-2025:0131-1 Security update for coredns | 1% Низкий | больше 1 года назад | ||
SUSE-SU-2025:0546-1 Security update golang-github-prometheus-prometheus | 1% Низкий | больше 1 года назад | ||
GHSA-29wx-vh33-7x7r Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations | CVSS3: 3.1 | 1% Низкий | почти 2 года назад | |
openSUSE-SU-2026:20099-1 Security update for coredns | 7 месяцев назад | |||
SUSE-SU-2025:1333-1 Security update for cosign | больше 1 года назад | |||
SUSE-SU-2025:0525-1 Security update for SUSE Manager Client Tools | больше 1 года назад | |||
openSUSE-SU-2026:20620-1 Security update for rclone | 4 месяца назад | |||
openSUSE-SU-2025:20117-1 Security update for trivy | 9 месяцев назад | |||
openSUSE-SU-2026:20798-1 Security update for trivy | 6 месяцев назад | |||
openSUSE-SU-2026:20654-1 Security update for grafana | 4 месяца назад |
Уязвимостей на страницу