Skip to content
This repository has been archived by the owner on Feb 22, 2024. It is now read-only.

Vulnerabilities found in PyJWT back in 2015 #119

Open
GeekOnGadgets opened this issue Apr 27, 2017 · 5 comments
Open

Vulnerabilities found in PyJWT back in 2015 #119

GeekOnGadgets opened this issue Apr 27, 2017 · 5 comments

Comments

@GeekOnGadgets
Copy link

Hi,

Thanks for awesome library. Just wanted to confirm something related to PyJWT library you are using in your project. Back in 2015 (https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/) Vulnerability issue was found with PyJWT not sure if that has been fixed now or still have to do a work around? Can't find much information out there.

Sorry for creating this as a issue. Hope you can provide with some info.

Thanks

@GeekOnGadgets GeekOnGadgets changed the title Vulnerabilities found in JWT back in 2015 Vulnerabilities found in PyJWT back in 2015 Apr 27, 2017
@yunderboy
Copy link

@GeekOnGadgets do you know whether this project is still going?

Thanks

@GeekOnGadgets
Copy link
Author

@yunderboy I don't think so. use https://github.com/vimalloc/flask-jwt-extended

@vimalloc
Copy link

vimalloc commented May 24, 2017

Not sure about this extension, but for what it's worth Flask JWT Extended is protected against this vulnerability.

@yunderboy
Copy link

@vimalloc, cool! Any idea on how long you might be maintaining the extension, and would you happen to need some help?

@vimalloc
Copy link

We use the extension at my job, so it will be maintained for quiet a while yet. And I would never turn down any help 👍

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Development

No branches or pull requests

3 participants