Skip to content

CVE-2023-1370 fix #914

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Feb 27, 2025
Merged

CVE-2023-1370 fix #914

merged 1 commit into from
Feb 27, 2025

Conversation

FerencKemeny
Copy link
Contributor

In my project where I used com.microsoft.azure:msal4j, I received Dependabot alerts that high severity CVE-2023-1370 is among my transitive dependencies. I found net.minidev:json-smart and according to the alert >= 2.5.0, < 2.5.2 are the affected version. So I upgraded it in your library and according to Dependabot security analyzis, this is fixed for now.

@FerencKemeny FerencKemeny requested a review from a team as a code owner February 26, 2025 22:44
@FerencKemeny
Copy link
Contributor Author

@microsoft-github-policy-service agree

@Avery-Dunn
Copy link
Collaborator

Thanks for updating the dependencies! We should have a hotfix out with these updates in the next day or two.

@Avery-Dunn Avery-Dunn merged commit 3eb10d1 into AzureAD:dev Feb 27, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants