Bug#1072123: jayway-jsonpath: CVE-2023-51074

2025-03-24 Thread Bastian Germann
Control: tags -1 wontfix Control: severity -1 important The Debian version is too old to contain this CVE. https://github.com/advisories/GHSA-pfh2-hfmq-phg5 has "Affected versions: >= 2.2.0, < 2.9.0" So this should not be RC for now. When the package is updated to another version make sure that t

Bug#1072123: jayway-jsonpath: CVE-2023-51074

2024-05-28 Thread Moritz Mühlenhoff
Source: jayway-jsonpath X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for jayway-jsonpath. CVE-2023-51074[0]: | json-path v2.8.0 was discovered to contain a stack overflow via the | Criteria.parse() method. https://github