5.8
CVSS V3
Status
Impact
Upgrading nimbus-jose-jwt to a secure version currently results in build failures due to unresolved classpath and dependency conflicts. The upstream project must first reconcile and adjust its dependency tree to support this version correctly. Once upstream dependencies are aligned, we can proceed with the update to remediate the vulnerability and apply the necessary patch.
Status