json-patch-1.13.jar触发CVE-2021-4279漏洞告警,确认修复方案及仓库?
json-patch依赖漏洞排查与修复说明
问题描述
OWASP依赖检查工具扫描失败,报错信息如下:
[ERROR] Failed to execute goal org.owasp:dependency-check-maven:7.4.3:check (default-cli) on project ins-app: [ERROR] [ERROR] One or more dependencies were identified with vulnerabilities that have a CVSS score greater than or equal to '8.0': [ERROR] [ERROR] json-patch-1.13.jar: CVE-2021-4279(9.8) CVE is https://nvd.nist.gov/vuln/detail/CVE-2021-4279
json-patch 1.13版本存在高危漏洞CVE-2021-4279,CVSS评分达9.8,触发了依赖检查拦截规则。
修复相关说明
- 疑似修复该漏洞的代码提交为Starcounter-Jack/JSON-Patch仓库下的
7ad6af4提交,但该仓库并非官方主仓库,是java-json-tools/json-patch的衍生仓库。 - 关于该漏洞的官方讨论、修复进度等内容,可查看java-json-tools/json-patch仓库的144号issue。
内容的提问来源于stack exchange,提问作者José Araújo
相关产品推荐
相关产品推荐

