| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| 2.0.1 - Security Fix.tar.gz | 2023-03-09 | 3.6 MB | |
| 2.0.1 - Security Fix.zip | 2023-03-09 | 3.6 MB | |
| README.md | 2023-03-09 | 538 Bytes | |
| Totals: 3 Items | 7.2 MB | 1 | |
What's Changed
- Security fix - CVE-2022-39227 by @codemation in https://github.com/codemation/easyauth/pull/95
Disclosure date
2023-03-07T18:48:04.077Z
Title
Vulnerable python_jwt dependecy version used, leading to CVE-2022-39227
Severity
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N = Critical (10)
Vulnerability Type
Authentication Bypass by Spoofing
Thanks to @notnci for locating & @psmoros for reporting.
Full Changelog: https://github.com/codemation/easyauth/compare/2.0.0...2.0.1