-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2024-57699 on Json-Path:2.9.0 #1031
Comments
Created a PR for the fix: #1030 |
Can you tell us by when we can expect a new release containing the vulnerability fix available on Maven Central? |
Hi @ukumar009 , following up on @jkoch70 's question— |
Hi @edwinlinson, to be honest. I can't merge the PR. I see there is one more waiting approval. I don't know who can help me with it. I don't know anything about release cycles of this jar. Sorry : ( |
CVE details can be seen here: https://nvd.nist.gov/vuln/detail/CVE-2024-57699
Fix is available in json-smart-v2: https://github.com/netplex/json-smart-v2?tab=readme-ov-file#v-252-2025-02-07
The text was updated successfully, but these errors were encountered: