We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Our OWASP scan detects two high vulnerabilities for the org.json:json:20240303 version:
https://nvd.nist.gov/vuln/detail/CVE-2022-45688 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-5072
At the same time https://security.snyk.io/package/maven/org.json:json doesn't show any vulnerabilities for the last version.
Could you please confirm or decline that mentioned vulnerabilities are false positive?
The text was updated successfully, but these errors were encountered:
@abanias Sorry for not replying sooner.
https://nvd.nist.gov/vuln/detail/CVE-2022-45688 Feel free to propose a fix for this.
https://nvd.nist.gov/vuln/detail/CVE-2022-45688
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-5072 I believe this was fixed in the 20231013 release.
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-5072
Sorry, something went wrong.
No branches or pull requests
Our OWASP scan detects two high vulnerabilities for the org.json:json:20240303 version:
https://nvd.nist.gov/vuln/detail/CVE-2022-45688
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-5072
At the same time https://security.snyk.io/package/maven/org.json:json doesn't show any vulnerabilities for the last version.
Could you please confirm or decline that mentioned vulnerabilities are false positive?
The text was updated successfully, but these errors were encountered: