Json-smart critical vulnerability - CVE-2021-27568

Issue #411 invalid
Vladimir Kryukov created an issue

Hi guys,

There is relatively fresh finding in your dependency - json-smart. Doesn’t look like they will fix it soon, maybe there is something we can do about to avoid the issue? This also related to com.nimbusds:oauth2-oidc-sdk

Open issue in json-smart-2 - https://github.com/netplex/json-smart-v2/issues/62
CVE - https://nvd.nist.gov/vuln/detail/CVE-2021-27568

Comments (3)

  1. Vladimir Dzhuvinov

    The bug was known prior to the CVE and there's been a fix since 2019. It might have come up in a security audit.

    Added an extra test here: fab8c51

  2. Vladimir Kryukov reporter

    Thank you for the reply, @Vladimir Dzhuvinov

    Nice to hear that the issue is not actual for the library.

  3. Log in to comment