Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update json-schema-validator in swagger-compat-spec-parser #463

Open
msymons opened this issue Jun 4, 2017 · 2 comments
Open

Update json-schema-validator in swagger-compat-spec-parser #463

msymons opened this issue Jun 4, 2017 · 2 comments

Comments

@msymons
Copy link
Contributor

msymons commented Jun 4, 2017

Update swagger-compat-spec-parser to use json-schema-validator v2.2.8 to address CVSS 3.0 level 5.4 security threat which originates from libphonenumber dependency.

Note that json-schema-validator has had a change of groudId from com.github.fge to com.github.java-json-tools. v2.2.8 uses libphonenumber v8.0.0 (threat was addressed in v7.2.3).

The libphonenumber transitive dependency results in a security alert from Nexus IQ OSS security scanning software. There is no CVE ID. Just a Sonatype problem code:

sonatype-2015-0090 - libphonenumber - A Cross Site Scripting vulnerability was found which is exploitable by manipulating the inputs. Reference:

google/libphonenumber#934

@msymons
Copy link
Contributor Author

msymons commented Jun 7, 2017

Reference PR #466

@Philzen
Copy link

Philzen commented May 31, 2024

This issue can be closed, can't it?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants