Skip to content

chore: Update jsrsasign due to CVE-2024-21484 Marvin attack of RSA and RSAOAEP decryption #1393

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Mar 23, 2024

Conversation

BSekula
Copy link
Contributor

@BSekula BSekula commented Jan 31, 2024

Fix for #1391

Updating jsrsasign version to 11.0.0

@rutalreja-deloitte
Copy link

Can we merge this please, this is a critical vulnerability

@BSekula
Copy link
Contributor Author

BSekula commented Feb 13, 2024

I do not have power to merge it.

@manfredsteyer could you please take a look?

@rutalreja-deloitte
Copy link

@manfredsteyer is there any blocker to merge this?

@zhenli-ong
Copy link

@manfredsteyer please help to complete the merge please

@loona-rvr
Copy link

up please @manfredsteyer @DenysVuika

@diogogasparr
Copy link

up @manfredsteyer @DenysVuika

@loona-rvr
Copy link

up again

@leogouveia
Copy link

leogouveia commented Mar 14, 2024

@manfredsteyer @DenysVuika
Any news about this PR?

@jjbravo
Copy link

jjbravo commented Mar 20, 2024

hi @manfredsteyer , please, helpme with this change.

@robke007
Copy link

@manfredsteyer, please make this a priority as it is critical vulnerability. Thanks!!

@manfredsteyer manfredsteyer merged commit 0335790 into manfredsteyer:master Mar 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

10 participants