CVE-2020-26160 on jwt-go flagged by scanners
helioloureiro opened this issue · 2 comments
helioloureiro commented
Hi,
Our scanners flagged the jwt-go vulnerability in file autorest/adal/token.go.
It is using a unmaintained jwt-go.
It should be using github.com/dgrijalva/jwt-go instead, where the fix is already delivered.
./helio
jhendrixMSFT commented
The module you cited is no longer maintained, the correct fork is github.com/golang-jwt/jwt.
helioloureiro commented
That came from the CVE itself.