Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

#687 update json-smart to fix CVE-2021-27568 #688

Merged
merged 1 commit into from
Apr 9, 2021

Conversation

mmm83
Copy link
Contributor

@mmm83 mmm83 commented Apr 6, 2021

CVE-2021-27568 has been fixed in latest releases of json-smart library. This will help with security violation in all projects that use JsonPath.

@kallestenflo kallestenflo merged commit 1987038 into json-path:master Apr 9, 2021
@ankampraveen
Copy link

ankampraveen commented Apr 12, 2021

@kallestenflo Looks like there is no new version released for this fix, what is the timeline for new version release ?
I still see 2.5.0 only.

@simone-dd
Copy link

@kallestenflo Looks like there is no new version released for this fix, what is the timeline for new version release ?
I still see 2.5.0 only.

+1.
It looks like this vulnerability has a score of 9.1 (Critical) (https://nvd.nist.gov/vuln/detail/CVE-2021-27568), which could be a dealbreaker for companies considering whether to use json-path or not.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants