-
-
Notifications
You must be signed in to change notification settings - Fork 60
Open
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency fileinvalidThis doesn't seem rightThis doesn't seem right
Description
The Rust rsa
crate has been found vulnerable in some form to the Marvin Attack.
The maintainers are actively working on a fix for this in RSA/394 .
As soon as this fix is in place, Rauthy will be updated with the new version to mitigate this attack.
A change to something like boring will not be done, because I want to stay pure Rust as much as possible and the compilation to musl targets should not be broken (which would happen with C bindings like boring).
Metadata
Metadata
Assignees
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency fileinvalidThis doesn't seem rightThis doesn't seem right