Skip to content

Conversation

@hackeramitkumar
Copy link

Currently we are using the RSA 0.9.2 which has high severity vulneravility :
https://rustsec.org/advisories/RUSTSEC-2023-0071

So in the latest release candidate they have addressed this mostly ( but still they have not updated the advisory . Since we are using openidconnect-rs crate in the AGNTCY/slim so this was becoming a blocker for us. So we have forked this repo and patched the RSA with the latest pre release version.

So I am raising a PR with the patch fix.
@maintainers please have a look into it.

hackeramitkumar and others added 4 commits July 30, 2025 19:59
Signed-off-by: amitami2 <amitami2@cisco.com>
Signed-off-by: amitami2 <amitami2@cisco.com>
Signed-off-by: amitami2 <amitami2@cisco.com>
@hackeramitkumar
Copy link
Author

@ramosbugs please have a look into it

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants