graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Graphql_engine | Hasura | * | 1.0.0 (excluding) |
Graphql_engine | Hasura | 1.0.0 (including) | 1.0.0 (including) |
Graphql_engine | Hasura | 1.0.0-beta.1 (including) | 1.0.0-beta.1 (including) |
Graphql_engine | Hasura | 1.0.0-beta.2 (including) | 1.0.0-beta.2 (including) |