Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

jwt-go library vulnerability CVE-2020-26160 #8336

Closed
reimda opened this issue Oct 29, 2020 · 0 comments · Fixed by #8337
Closed

jwt-go library vulnerability CVE-2020-26160 #8336

reimda opened this issue Oct 29, 2020 · 0 comments · Fixed by #8337
Labels
bug unexpected problem or unintended behavior

Comments

@reimda
Copy link
Contributor

reimda commented Oct 29, 2020

Security scanning turned up that telegraf uses a version of the jwt-go library that has a high severity vulnerability. It's not clear if the vulnerability can be exploited in telegraf.

Details at https://nvd.nist.gov/vuln/detail/CVE-2020-26160

jwt-go version 4.0.0-preview1 has a fix. Telegraf should update to this version or newer.

@reimda reimda added the bug unexpected problem or unintended behavior label Oct 29, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug unexpected problem or unintended behavior
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant