PyPi: More.Jwtauth

PVE-2022-49499

Safety vulnerability ID: 49499

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Jun 19, 2022 Updated at Mar 03, 2024

Advisory

More.jwtauth 0.9 passes algorithm explicit to 'jwt.decode()' to avoid access control bypa…

[This advisory has been limited. Please create a free account to view the full advisory.]

Affected package

more.jwtauth

Latest version: 0.14

JWT Access Auth Identity Policy for Morepath

Affected versions

Fixed versions

Vulnerability changelog

---------------- - **New:** Add an API to refresh the JWT token (see issue `6`_). Thi…

[This text has been limited. Please create a free account to view the full text.]

Resources