Debian 12 — golang-github-dgrijalva-jwt-go — vulnerability — patch and remediation guide
🟢 Low ⏱ 5–15 min Last verified: 9 February 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read • Source: Debian Security Tracker Related CVEs: CVE-2020-26160 Upstream summary: jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m["aud"] (which is allowed by the specification). Because the type […]