Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency on the vulnerable org.json:json:20220320 #99

Closed
alok1111 opened this issue Feb 8, 2024 · 8 comments
Closed

Dependency on the vulnerable org.json:json:20220320 #99

alok1111 opened this issue Feb 8, 2024 · 8 comments

Comments

@alok1111
Copy link

alok1111 commented Feb 8, 2024

CVE-2023-5072
CVE-2022-45688

Expected Behavior

No dependencies with vulnerabilities

Current Behavior

2 High vulnerabilities

Possible Solution

Update org.json:json to the recent version

@alok1111
Copy link
Author

Hello Team, can you please provide your thoughts about the issue? Is it safe to run the client in production? Do you have plans to update the dependency?

@alok1111
Copy link
Author

Also, I noticed that you already have a PR that addresses one of the vulnerabilities, but you didn't merge it, provide any response or fix the issue yourself. Why?

@izaaz
Copy link
Contributor

izaaz commented Feb 16, 2024

@alok1111 thanks for creating this ticket. I am taking a look at this and will update soon.

@alok1111
Copy link
Author

@izaaz is there any news?

@izaaz
Copy link
Contributor

izaaz commented Feb 27, 2024

@alok1111 the patch was just released in version 1.12.1

@izaaz izaaz closed this as completed Feb 27, 2024
@izaaz
Copy link
Contributor

izaaz commented Feb 28, 2024

Correction. The package has been deployed to a staging env. I'll update this issue once it's generally available.

@alok1111
Copy link
Author

@izaaz thank you for the update.
1.21.1 fixes only one vulnerability - CVE-2022-45688. Would please fix also CVE-2023-5072? To do that you need to upgrade org.json:json at least to 20231013.
Also noticed that the org.json:json versions are out of sync between demo, main and test. So probably the project tests run on a wrong version.

@izaaz
Copy link
Contributor

izaaz commented Feb 28, 2024

Thanks @alok1111. All packages are updated and use the version 20231013. The latest version 1.12.2 is now available.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants