Both upickle and ujson have security vulnerablities
plokhotnyuk opened this issue · 6 comments
plokhotnyuk commented
Please, see com-lihaoyi/upickle#416 (comment)
szymon-rd commented
Hi! Thank you for creating the issue. We are aware, and it's important for us to address it with the library maintainers. I will keep this issue as a place to post updates.
plokhotnyuk commented
Fixed in upickle v3.0.0 https://github.com/com-lihaoyi/upickle/releases/tag/3.0.0
bishabosha commented
I don't think this should be closed until the patched version is part of the build?
plokhotnyuk commented
@bishabosha You are right.
Also, need to check for other possible vulnerabilities like DoS by parsing of too big numbers or too deeply nested JSON arrays/objects.
szymon-rd commented
Update to upickle 3.0.0 was merged.
szymon-rd commented
@plokhotnyuk that's a good idea for another issue