CVE-2022-23529 (High) detected in jsonwebtoken-8.5.1.tgz - ibmcloud-appid

377 Views Asked by At

We are getting there is one high vulnerability related to jsonwebtoken and which is dependent package of ibmcloud-appid. ibmcloud-appid I have already upgraded to latest but still in package-lock.json jsonwebtoken version is 8.5.1. Here in vulnerability jsonwebtoken is recommend to upgrade version to 9.0.0. So how i can upgrade package-lock.json dependent package, as that is not present in package.json?

1

There are 1 best solutions below

0
On

A new version of ibmcloud-appid with the fixed vulnerability will be released soon. Please keep an eye on the following issue for updates

https://github.com/ibm-cloud-security/appid-serversdk-nodejs/issues/286