You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The project includes sources from the Jansson project, located in the webdis/src/jansson/ directory. However, those sources are old and contain unpatched vulnerabilities like CVE-2016-4425 and CVE-2013-6401. If Jansson sources are used somewhere, I recommend updating them to the latest version. My report was primarily based on a static analysis tool developed at CAST, which flagged the potential vulnerability due to similarities in the codebase.
The text was updated successfully, but these errors were encountered:
From these two links, it does not seem like they would apply to this newer version of the library: the first says "Jansson 2.7 and earlier", and the second "Jansson, possibly 2.4 and earlier".
I'll make sure to finish validating these contributions so they can get merged.
The project includes sources from the Jansson project, located in the
webdis/src/jansson/
directory. However, those sources are old and contain unpatched vulnerabilities like CVE-2016-4425 and CVE-2013-6401. If Jansson sources are used somewhere, I recommend updating them to the latest version. My report was primarily based on a static analysis tool developed at CAST, which flagged the potential vulnerability due to similarities in the codebase.The text was updated successfully, but these errors were encountered: