Skip to content

Use latest json-smart lib to fix CVE-2024-57699#2596

Merged
naveentatikonda merged 1 commit intoopensearch-project:mainfrom
Vikasht34:CVE
Mar 12, 2025
Merged

Use latest json-smart lib to fix CVE-2024-57699#2596
naveentatikonda merged 1 commit intoopensearch-project:mainfrom
Vikasht34:CVE

Conversation

@Vikasht34
Copy link
Copy Markdown
Collaborator

Description

json-path 2.9.0 has been flagged in GHSA-pq2g-wx69-c263. They do not have fix yet, and their devs suggest to switch to json-smart json-path/JsonPath#1031.

We need to have this library for ml-commons, follow their strategy: keep json-path, but excluding json-smart part of it, and include json-mart of the proper version separately.

Picking up version of json-smart from the OS core, they added in the recent PR opensearch-project/OpenSearch#17569

Related Issues

Resolves #[Issue number to be closed when this PR is merged]

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: Vikasht34 <viktari@amazon.com>
@naveentatikonda naveentatikonda merged commit 4e68f3e into opensearch-project:main Mar 12, 2025
37 of 51 checks passed
kotwanikunal pushed a commit to kotwanikunal/k-NN that referenced this pull request Jun 2, 2025
kotwanikunal pushed a commit to kotwanikunal/k-NN that referenced this pull request Jun 2, 2025
)

Signed-off-by: Kunal Kotwani <kkotwani@amazon.com>
naveentatikonda pushed a commit that referenced this pull request Jun 2, 2025
* Increment version to 2.19.3-SNAPSHOT

Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com>

* Use latest json-smart lib to fix  CVE-2024-57699 (#2596)

Signed-off-by: Kunal Kotwani <kkotwani@amazon.com>

* Manually add in the CVE fix version for json-smart

Signed-off-by: Kunal Kotwani <kkotwani@amazon.com>

---------

Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com>
Signed-off-by: Kunal Kotwani <kkotwani@amazon.com>
Co-authored-by: opensearch-ci-bot <opensearch-infra@amazon.com>
Co-authored-by: Vikasht34 <viktari@amazon.com>
luyuncheng pushed a commit to luyuncheng/k-NN-1 that referenced this pull request Jun 18, 2025
jingqimao77-spec pushed a commit to jingqimao77-spec/k-NN that referenced this pull request Mar 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants