Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update com.nimbusds:nimbus-jose-jwt to address vulnerability #8947

Open
benkay opened this issue Jul 29, 2024 · 1 comment
Open

Update com.nimbusds:nimbus-jose-jwt to address vulnerability #8947

benkay opened this issue Jul 29, 2024 · 1 comment
Labels

Comments

@benkay
Copy link

benkay commented Jul 29, 2024

Our security team flagged com.nimbusds:nimbus-jose-jwt as having a known vulnerability. Looks like the 3ds2 dependency depends on an old version (9.21).

I assume it's safe to force the latest version (9.40) ourselves, but it would be helpful if it was updated within this SDK so we can be sure there are no compatibility issues.

@benkay benkay added the bug label Jul 29, 2024
@jaynewstrom-stripe
Copy link
Collaborator

Hi @benkay

This is on our list to update.

In the meantime, you can depend on a newer version directly in your build.gradle, which will transitively update the version, and no longer have a vulnerability listed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants