Skip to content

2.0.1 - Security Fix

Choose a tag to compare

@codemation codemation released this 09 Mar 15:51
· 4 commits to main since this release
e8e8aa0

What's Changed

Disclosure date

2023-03-07T18:48:04.077Z

Title

Vulnerable python_jwt dependecy version used, leading to CVE-2022-39227

Severity

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N = Critical (10)

Vulnerability Type

Authentication Bypass by Spoofing

Thanks to @notnci for locating & @psmoros for reporting.

Full Changelog: 2.0.0...2.0.1