Azure/go-autorest

CVE-2020-26160 on jwt-go flagged by scanners

helioloureiro opened this issue · 2 comments

Hi,

Our scanners flagged the jwt-go vulnerability in file autorest/adal/token.go.

It is using a unmaintained jwt-go.

It should be using github.com/dgrijalva/jwt-go instead, where the fix is already delivered.

./helio

The module you cited is no longer maintained, the correct fork is github.com/golang-jwt/jwt.

That came from the CVE itself.