Uploaded image for project: 'Calcite'
  1. Calcite
  2. CALCITE-6124

Upgrade json-path version to 2.8.0

    XMLWordPrintableJSON

Details

    Description

      json-path has critical bugs in 2.7.0 used in Caclite project, see https://github.com/json-path/JsonPath/issues/906

      cve: https://www.cve.org/CVERecord?id=CVE-2023-1370

      the current version is vulnerable to Denial of Service (DoS) due to a StackOverflowError when parsing a deeply nested JSON array or object, and the issue has been fixed in 2.8.0.

      We should bump to to the latest version to resolve it.

      Attachments

        Issue Links

          Activity

            People

              liyubin117 Yubin Li
              liyubin117 Yubin Li
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: