VDB
Sign up
—

GO-2022-0564

Signature forgery in github.com/biscuit-auth/biscuit-go

Details

An attacker can forge Biscuit v1 tokens with any access level.

There is no known workaround for Biscuit v1. The Biscuit v2 specification avoids this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/biscuit-auth/biscuit-go
Introduced in: 0

No fixed version published yet for github.com/biscuit-auth/biscuit-go (go modules). Pin to a known-safe version or switch to an alternative.

References