Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix CVE-2021-27568 for net.minidev:json-smart:2.3 #85

Closed
r0bb3n opened this issue May 1, 2021 · 0 comments · Fixed by #88
Closed

Fix CVE-2021-27568 for net.minidev:json-smart:2.3 #85

r0bb3n opened this issue May 1, 2021 · 0 comments · Fixed by #88
Assignees
Labels
security Pull requests that address a security vulnerability

Comments

@r0bb3n
Copy link
Owner

r0bb3n commented May 1, 2021

Even if it is only a transitive test dependency, it should be fixed (and make blackduck green again).

CVE-2021-27568
GitHub issue in json-smart repo

fixed version: 2.3.1 (but also 2.4.1)

@r0bb3n r0bb3n added the enhancement New feature or request label May 1, 2021
@r0bb3n r0bb3n self-assigned this May 1, 2021
@r0bb3n r0bb3n added dependencies Pull requests that update a dependency file and removed enhancement New feature or request labels May 1, 2021
@r0bb3n r0bb3n added security Pull requests that address a security vulnerability and removed dependencies Pull requests that update a dependency file labels May 2, 2021
@r0bb3n r0bb3n closed this as completed in #88 May 4, 2021
r0bb3n added a commit that referenced this issue May 4, 2021
…son-smart

GH-85 update json-smart to fixed version 2.3.1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant