mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-08-31 03:45:41 +00:00
3c9dd88058
Reject JSON Web Key documents passed directly as HMAC secrets. This prevents public asymmetric JWK data from being reused as an HMAC key when an application permits mixed symmetric and asymmetric algorithms. This patch applies the relevant subset of the upstream 2.13.0 fix. The upstream commit is referenced in [1], and the public advisory is referenced in [2]. [1] https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81 [2] https://github.com/advisories/GHSA-xgmm-8j9v-c9wx Signed-off-by: Hetvi Thakar <hthakar@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>