Skip to content

Consider updating net.minidev:json-smart to 2.5.2 to address CVE-2024-57699 #1033

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
hvub opened this issue Mar 7, 2025 · 6 comments
Open

Comments

@hvub
Copy link

hvub commented Mar 7, 2025

Consider updating net.minidev:json-smart to 2.5.2 to address CVE-2024-57699:

jsonSmart : 'net.minidev:json-smart:2.5.1',

-Thanks.

@hvub hvub changed the title Consider updating minidev.json-smart to 2.5.2 to address CVE-2024-57699 Consider updating net.minidev:json-smart to 2.5.2 to address CVE-2024-57699 Mar 7, 2025
@hvub hvub changed the title Consider updating net.minidev:json-smart to 2.5.2 to address CVE-2024-57699 Consider updating net.minidev:json-smart to 2.5.2 to address CVE-2024-57699 Mar 7, 2025
@lrozenblyum
Copy link

lrozenblyum commented Mar 7, 2025

@lrozenblyum
Copy link

According to #1030 (comment) it's enough to bump a new version. So #1030 should handle current issue

@ronlangeveld
Copy link

Given the fact that json-path is a managed dependency with spring-boot-starter-parent many projects now are dealing with it with tempory fixes. Since the bump is just trivial I guess most people wouldn't mind a minor bump to 2.9.1 in the short term. Don't give Spring an excuse to start looking for alternate libraries ;)

@afiller
Copy link

afiller commented Apr 16, 2025

Any updates on this topic? We are also waiting for an update.

@dyrnq
Copy link

dyrnq commented Apr 22, 2025

stare

@kivan-mih
Copy link

Guys, please do the fix, temporary solutions due to this in the code, which is not good

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants