You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Bump PyJWT to 2.10.1 in .ci/metrics/requirements.lock.txt (#16718)
PR to bump dependency version to resolve security vulnerability found.
In current version, The wrong string if check is run for iss checking,
resulting in "acb" being accepted for "_abc_".
Additional details:
Weaknesses: CWE-697
CVE ID: CVE-2024-53861
0 commit comments