16
Views
0
Comments
[JWT] Vulnerability found in Forge Component
jwt
Service icon
Forge asset by João Almeida
Application Type
Service

Hi there Maxime,A vulnerability was found in the recent version of the Forge Component JWT v4.1.11It contains the  libraries BouncyCastle.Crypto v1.8.9 and JWT v 1.3.3 which contain vulnerabilities.

BouncyCastle.Cryptohttps://nvd.nist.gov/vuln/detail/CVE-2020-26939

&

JWT 1.3.3 is an old and unsupported version of the jwt-dotnet library and is flagged by NuGet as having known security vulnerabilities. Any chance a new version on the .net library can be implemented in your Forge Component?Thank you 

Community GuidelinesBe kind and respectful, give credit to the original source of content, and search for duplicates before posting.