From c812b8b15af58839f9071631cb259f2fd12d003a Mon Sep 17 00:00:00 2001 From: John-Michael Faircloth Date: Thu, 27 Jun 2024 12:32:44 -0500 Subject: [PATCH] docs: update fix versions for auth/jwt change (#27630) --- .../partials/known-issues/1_16-jwt_auth_bound_audiences.mdx | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/website/content/partials/known-issues/1_16-jwt_auth_bound_audiences.mdx b/website/content/partials/known-issues/1_16-jwt_auth_bound_audiences.mdx index 78fda89c074e..afc5506f7100 100644 --- a/website/content/partials/known-issues/1_16-jwt_auth_bound_audiences.mdx +++ b/website/content/partials/known-issues/1_16-jwt_auth_bound_audiences.mdx @@ -4,13 +4,15 @@ - 1.15.9 - 1.15.10 +- 1.15.11 - 1.16.3 - 1.16.4 +- 1.16.5 #### Issue A behavior change was made in the jwt auth plugin to address CVE-2024-5798. Since the behavior change was a breaking change, we reverted the change in -the versions 1.15.11 and 1.16.5 and later. However, the behavior change will go +the versions 1.15.12 and 1.16.6 and later. However, the behavior change will go into effect in 1.17. The new behavior requires that the `bound_audiences` parameter of "jwt" roles