scala/toolkit

Both upickle and ujson have security vulnerablities

plokhotnyuk opened this issue · 6 comments

Hi! Thank you for creating the issue. We are aware, and it's important for us to address it with the library maintainers. I will keep this issue as a place to post updates.

I don't think this should be closed until the patched version is part of the build?

@bishabosha You are right.

Also, need to check for other possible vulnerabilities like DoS by parsing of too big numbers or too deeply nested JSON arrays/objects.

Update to upickle 3.0.0 was merged.

@plokhotnyuk that's a good idea for another issue