Uploaded image for project: 'Apache Avro'
  1. Apache Avro
  2. AVRO-3874

Bump minimum Newtonsoft version because of severe vulnerability

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Duplicate
    • None
    • 1.11.4
    • csharp

    Description

      Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS).

       

      https://github.com/advisories/GHSA-5crp-9r3c-p9vr

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              zoltan_csizmadia@yahoo.com Zoltan Csizmadia
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 24h
                  24h
                  Remaining:
                  Time Spent - 0.5h Remaining Estimate - 23.5h
                  23.5h
                  Logged:
                  Time Spent - 0.5h Remaining Estimate - 23.5h
                  0.5h