Skip to content

Conversation

@FerencKemeny
Copy link
Contributor

In my project where I used com.microsoft.azure:msal4j, I received Dependabot alerts that high severity CVE-2023-1370 is among my transitive dependencies. I found net.minidev:json-smart and according to the alert >= 2.5.0, < 2.5.2 are the affected version. So I upgraded it in your library and according to Dependabot security analyzis, this is fixed for now.

@FerencKemeny FerencKemeny requested a review from a team as a code owner February 26, 2025 22:44
@FerencKemeny
Copy link
Contributor Author

@microsoft-github-policy-service agree

@Avery-Dunn
Copy link
Contributor

Thanks for updating the dependencies! We should have a hotfix out with these updates in the next day or two.

@Avery-Dunn Avery-Dunn merged commit 3eb10d1 into AzureAD:dev Feb 27, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants