-
Notifications
You must be signed in to change notification settings - Fork 220
Closed
Description
There is a vulnerability in the transitive dependency JSONPath
Description
The latest possible version of JSONPath that can be installed is 7.2.0 because of the following conflicting dependencies:
- [email protected] requires jsonpath-plus@^7.0.0 via a transitive dependency on [email protected]
- [email protected] requires jsonpath-plus@^7.2.0 via a transitive dependency on [email protected]
The earliest fixed version of JSONPath is 10.0.7.
The vulnerability was first published in November 2024.
See CVE-2024-21534 for more details.
ynishimura and lym953
Metadata
Metadata
Assignees
Labels
No labels