MEDIUM5.3
GHSA-pfh2-hfmq-phg5
json-path Out-of-bounds Write vulnerability
Quick fix
GHSA-pfh2-hfmq-phg5 — com.jayway.jsonpath:json-path: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.9.0</version> for com.jayway.jsonpath:json-pathDetails
json-path v2.8.0 was discovered to contain a stack overflow via the `Criteria.parse()` method.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/com.jayway.jsonpath:json-path
Introduced in:
2.2.0Fixed in: 2.9.0Fix
# pom.xml: bump <version>2.9.0</version> for com.jayway.jsonpath:json-pathReferences
- https://nvd.nist.gov/vuln/detail/CVE-2023-51074[ADVISORY]
- https://github.com/json-path/JsonPath/issues/973[WEB]
- https://github.com/json-path/JsonPath/commit/71a09c1193726c010917f1157ecbb069ad6c3e3b[WEB]
- https://github.com/json-path/JsonPath[PACKAGE]
- https://github.com/json-path/JsonPath/releases/tag/json-path-2.9.0[WEB]