CVE-2020-15222: Improper Authentication
(updated )
In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go), when using private_key_jwt
authentication the uniqueness of the jti
value is not checked.
References
Detect and mitigate CVE-2020-15222 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →