Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update jsonpath-plus #5115

Merged
merged 3 commits into from
Feb 19, 2025
Merged

Update jsonpath-plus #5115

merged 3 commits into from
Feb 19, 2025

Conversation

lukaskl
Copy link
Contributor

@lukaskl lukaskl commented Feb 19, 2025

Recreated equivalent PR to #5036

This PR aims to address CVE-2025-1302, which is needed because the previous patch to address CVE-2024-21534 was incomplete.

@lukaskl lukaskl force-pushed the update-jsonpath-plus branch from 1078068 to d74586e Compare February 19, 2025 10:32
@iclanton iclanton enabled auto-merge (squash) February 19, 2025 17:52
@iclanton iclanton merged commit ee78b67 into microsoft:main Feb 19, 2025
5 checks passed
@lukaskl lukaskl deleted the update-jsonpath-plus branch February 19, 2025 19:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Closed
Development

Successfully merging this pull request may close these issues.

[rush] CVE-2025-1302 jsonpath-plus is again flagged as vulnerable
2 participants