Uploaded image for project: 'mod-audit'
  1. mod-audit
  2. MODAUD-135

json-path 2.7.0 fixing json-smart DoS CVE-2021-27568

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • TBD
    • Resolution: Done
    • None
    • None
    • Firebird
    • Related dependency upgrade

    Description

      Upgrade com.jayway.jsonpath:json-path from 2.5.0 to 2.7.0. This indirectly upgrades net.minidev:json-smart from 2.3 to 2.4.7 fixing Denial of Service (DoS): https://nvd.nist.gov/vuln/detail/cve-2021-27568

      Adding <scope>test</scope> as json-path/json-smart is used in tests only.

      TestRail: Results

        Attachments

          Activity

            People

              khandramai Viachaslau Khandramai
              julianladisch Julian Ladisch
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                TestRail: Runs

                  TestRail: Cases