-
Notifications
You must be signed in to change notification settings - Fork 85
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2022-45688: A stack overflow in the XML.toJSONObject component #1968
Comments
Thanks for reporting this @AlaaAttya |
I don't see "org.json:json" in the link. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45688 Is hutool-json related to "org.json:json"? |
It mentions stleary/JSON-java#708 |
https://github.com/stleary/JSON-java/blob/master/pom.xml is org.json:json. Thank you. |
java-bigquerystorage don't use XML.toJSONObject. Closing this because the CVE doesn't affect Bigquery Storage library. |
There's a CVE raised for
org.json:json:jar:20220924:compile
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45688
The text was updated successfully, but these errors were encountered: