Package
argo-cd-fips-2.12-repo-server
Component
github.com/golang-jwt/jwt
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The dependency causing this CVE, golang-jwt/jwt v3.2.2, is introduced in several places in the argo-cd project. Due to functional changes required to move away from v3 to v4/v5, upstream maintainers are required to implement.
Status
Status
Fixed version
2.12.10-r8Status