Skip to content

org.json:json transitive dependency has security vulnerabilities #397

@lukewpatterson

Description

@lukewpatterson

From mvn dependency:tree

[INFO] +- com.plaid:plaid-java:jar:17.0.0:compile
[INFO] |  +- org.apache.oltu.oauth2:org.apache.oltu.oauth2.client:jar:1.0.1:compile
[INFO] |  |  +- org.apache.oltu.oauth2:org.apache.oltu.oauth2.common:jar:1.0.1:compile
[INFO] |  |  |  +- org.json:json:jar:20140107:compile

My build report is showing these vulnerabilities:

org.json:json release notes

They just released org.json:json:20231013, which I think fixes all the vulnerabilities.

Not sure if related to #283, is the intermediate dependency not even needed anyways?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions