10-01-2023 20:59
via
nakedsecurity.sophos.com
Popular JWT cloud security library patches “remote” code execution hole
It's remotely triggerable, but attackers would already have pretty deep network access if they could "prime" your server for compromise.
Read more »