Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Reference to Microsoft.IdentityModel.JsonWebTokens #771

Closed
jhudsoncedaron opened this issue Dec 3, 2024 · 3 comments
Closed

Upgrade Reference to Microsoft.IdentityModel.JsonWebTokens #771

jhudsoncedaron opened this issue Dec 3, 2024 · 3 comments
Assignees
Labels
status: waiting for feedback waiting for feedback from the submitter

Comments

@jhudsoncedaron
Copy link

Package 'Microsoft.IdentityModel.JsonWebTokens' 6.19.0 has a known moderate severity vulnerability, GHSA-59j7-ghrg-fj52

We are looking at a must upgrade to 8.21 which is an ABI change; due to the way the loader works no exceptions can be made.

Failure to update the JWT package may resulting in dropping Twilio's product altogether.

@sbansla
Copy link
Contributor

sbansla commented Feb 19, 2025

@jhudsoncedaron Let me create a ticket internally, We will fix this shortly.

@sbansla sbansla self-assigned this Feb 19, 2025
@sbansla sbansla added status: work in progress Twilio or the community is in the process of implementing status: waiting for feedback waiting for feedback from the submitter and removed status: work in progress Twilio or the community is in the process of implementing labels Feb 20, 2025
@sbansla
Copy link
Contributor

sbansla commented Feb 21, 2025

upgraded System.IdentityModel.Tokens.Jwt to 8.3.1
in twilio-csharp version 7.8.5

@sbansla sbansla closed this as completed Feb 24, 2025
@jhudsoncedaron
Copy link
Author

jhudsoncedaron commented Feb 24, 2025

Oh nice. The team member who uses that component will surely upgrade very soon.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status: waiting for feedback waiting for feedback from the submitter
Projects
None yet
Development

No branches or pull requests

2 participants