-
Notifications
You must be signed in to change notification settings - Fork 205
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Workflow failed: OWASP dependency check (daily) (#892) #4074
Comments
Has to do with CVE-2024-57699. This is a high-risk issue and so a patch is needed quickly. Please fix this. |
json-smart is a transitive dependency: Application Insights -> Azure Identity -> msal4j -> json-smart Our usage of the json-smart library doesn't accept any user input. So, we don't think that the Application Insights Java agent can be impacted by this CVE. We will update the more recent version in the next release. |
Thanks. Very annoying for us as I can't override our pipeline to accept this. So I can't deploy my service due to this. Even though there actually is no issue. |
@jeanbisutti (update: fix wrong mention) |
@gyula-kelemen I don't know anything about that |
Ahh, sorry wrong tag. |
There is a new version of json-smart. So it is very easy to fix. If not forced then I also see that Msal4j is updated. Probably for this but I did not check that. Also azure-identity seems to be updated. |
@gyula-kelemen #4077 will be included in our next release |
See OWASP dependency check (daily) #892.
The text was updated successfully, but these errors were encountered: