-
Story
-
Resolution: Done
-
Undefined
-
None
-
None
-
False
-
-
False
-
None
-
None
-
None
-
None
-
None
✗ Low severity vulnerability found in github.com/golang-jwt/jwt/v4
38
Description: Insufficient Documentation of Error Handling Techniques
39
Info: https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGOLANGJWTJWTV4-8341242
40
Introduced through: github.com/Azure/go-autorest/autorest@0.11.29, github.com/Azure/go-autorest/autorest/azure@0.11.29, github.com/Azure/go-autorest/autorest/azure/auth@0.5.13, github.com/Azure/azure-sdk-for-go/services/compute/mgmt/2019-12-01/compute@68.0.0, github.com/Azure/azure-sdk-for-go/services/dns/mgmt/2018-05-01/dns@68.0.0, github.com/openshift/installer/pkg/asset/installconfig/azure@#dfd4c085a721, github.com/openshift/installer/pkg/destroy/azure@#dfd4c085a721, github.com/openshift/installer/pkg/asset/machines/aws@#dfd4c085a721, github.com/openshift/installer/pkg/asset/machines/openstack@#dfd4c085a721, github.com/openshift/installer/pkg/asset/machines/vsphere@#dfd4c085a721, github.com/openshift/installer/pkg/asset/machines/azure@#dfd4c085a721, github.com/openshift/installer/pkg/asset/machines/gcp@#dfd4c085a721
41
From: github.com/Azure/go-autorest/autorest@0.11.29 > github.com/Azure/go-autorest/autorest/adal@0.9.23 > github.com/golang-jwt/jwt/v4@4.5.0
42
From: github.com/Azure/go-autorest/autorest/azure@0.11.29 > github.com/Azure/go-autorest/autorest@0.11.29 > github.com/Azure/go-autorest/autorest/adal@0.9.23 > github.com/golang-jwt/jwt/v4@4.5.0
43
From: github.com/Azure/go-autorest/autorest/azure/auth@0.5.13 > github.com/Azure/go-autorest/autorest/azure/cli@0.4.6 > github.com/Azure/go-autorest/autorest/adal@0.9.23 > github.com/golang-jwt/jwt/v4@4.5.0
44
and 9 more...
45
Fixed in: 4.5.1
46
I feel like we were ignoring low-sev dep vulns, but...