Skip to content

Dependency jsrsasign of angular-oauth2-oidc-jwks has a critical vulnerability #1061

@jmac105

Description

@jmac105

Describe the bug
angular-oauth2-oidc-jwks has a dependency "jsrsasign": "^8.0.12"
CVE-2021-30246 has been published with a CVSS 3.x score of 9.1 and affects all versions of jsrsasign prior to 10.2.0

References
See https://nvd.nist.gov/vuln/detail/CVE-2021-30246 & GHSA-27fj-mc8w-j9wg

I'll try and a raise a PR to update that dependency later today as it would be great to get this resolved ASAP

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugFor tagging faulty or unexpected behavior.dependenciesPull requests that update a dependency file

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions