You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Overview net.minidev:json-smart is a Java JSON parser. Affected versions of this package are vulnerable to Denial of Service (DoS) due to a StackOverflowError when parsing a deeply nested JSON array or object.
NOTE: Although this vulnerability was fixed in version 2.4.9 the maintainer recommends upgrading to 2.4.10, due to a remaining bug.
Overview
net.minidev:json-smart is a Java JSON parser. Affected versions of this package are vulnerable to Denial of Service (DoS) due to a StackOverflowError when parsing a deeply nested JSON array or object.
NOTE: Although this vulnerability was fixed in version 2.4.9 the maintainer recommends upgrading to 2.4.10, due to a remaining bug.
Introduced through: org.flywaydb:[email protected]
Fixed in: net.minidev:[email protected]
Detailed paths
Introduced through: unknown:[email protected] › org.flywaydb:[email protected] › com.microsoft.azure:[email protected] › net.minidev:[email protected]
Fix: Your dependencies are out of date, otherwise you would be using a newer net.minidev:json-smart than net.minidev:[email protected]. Try reinstalling your dependencies. If the problem persists, one of your dependencies may be bundling outdated modules.
Introduced through: unknown:[email protected] › org.flywaydb:[email protected] › com.microsoft.azure:[email protected] › com.nimbusds:[email protected] › net.minidev:[email protected]
https://app.snyk.io/org/fecgov/project/e6c155e9-f0ac-4a49-98fa-83c24f5b74b3#issue-SNYK-JAVA-NETMINIDEV-3369748
Action items:
Completion criteria
The text was updated successfully, but these errors were encountered: