io.acryl:datahub-client@0.8.44 vulnerabilities

  • latest version

    15.0.4

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    2 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the io.acryl:datahub-client package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Incorrect Implementation of Authentication Algorithm

    Affected versions of this package are vulnerable to Incorrect Implementation of Authentication Algorithm due to the 'StatelessTokenService' class not verifying the signature of JWT tokens. 'StatelessTokenService' class is using the parse method of io.jsonwebtoken.JwtParser, which does not perform a verification of the cryptographic token signature.

    How to fix Incorrect Implementation of Authentication Algorithm?

    Upgrade io.acryl:datahub-client to version 0.8.45 or higher.

    [,0.8.45)