github spiffe/spire v1.12.3

latest releases: v1.12.5, v1.13.0, v1.12.4...
2 months ago

Security

  • Fixed an issue in spire-agent where the WorkloadAPI.ValidateJWTSVID endpoint did not enforce the presence of the exp (expiration) claim in JWT-SVIDs, as required by the SPIFFE specification.
    This vulnerability has limited impact: by default, SPIRE does not issue JWT-SVIDs without an expiration claim. Exploitation would require federating with a misconfigured or non-compliant trust domain.
    Thanks to Edoardo Geraci for reporting this issue.

Don't miss a new spire release

NewReleases is sending notifications on new releases.