-
Notifications
You must be signed in to change notification settings - Fork 1.7k
Consider updating net.minidev:json-smart
to 2.5.2 to address CVE-2024-57699
#1033
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
net.minidev:json-smart
to 2.5.2 to address CVE-2024-57699
IMHO it's not enough |
According to #1030 (comment) it's enough to bump a new version. So #1030 should handle current issue |
Given the fact that json-path is a managed dependency with spring-boot-starter-parent many projects now are dealing with it with tempory fixes. Since the bump is just trivial I guess most people wouldn't mind a minor bump to 2.9.1 in the short term. Don't give Spring an excuse to start looking for alternate libraries ;) |
Any updates on this topic? We are also waiting for an update. |
stare |
Guys, please do the fix, temporary solutions due to this in the code, which is not good |
Consider updating
net.minidev:json-smart
to 2.5.2 to address CVE-2024-57699:JsonPath/build.gradle
Line 15 in 45333e0
-Thanks.
The text was updated successfully, but these errors were encountered: