chartmuseum-fips
Chainguard
7.5
CVSS V3
Status
Impact
The CVE related to the version 'github.com/golang-jwt/jwt v3.2.2+incompatible' is due to a transient dependency of github.com/chartmuseum/auth@v0.5.0. Upstream is required to do code changes to change the dependency, or the dependency needs to be updated to stop making use of github.com/golang-jwt/jwt v3.x.
Status
Status
Fixed version
0.16.2-r14Status