Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade cJSON v1.7.7=>v1.7.11 to address security vulnerabilities #1595

Closed
wants to merge 1 commit into from

Conversation

dkalinowski
Copy link

@dkalinowski dkalinowski commented Mar 18, 2021

Issue: #1594

Description of changes:
Upgrade cJSON dependency to version which addresses security isssue: https://github.com/DaveGamble/cJSON/releases/tag/v1.7.11

CVE-2019-11835 cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
CVE-2019-11834 cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.

Check all that applies:

  • Did a review by yourself.
  • Added proper tests to cover this PR. (If tests are not applicable, explain.)
  • Checked if this PR is a breaking (APIs have been changed) change.
  • Checked if this PR will not introduce cross-platform inconsistent behavior.
  • Checked if this PR would require a ReadMe/Wiki update.

Check which platforms you have built SDK on to verify the correctness of this PR.

  • Linux
  • Windows
  • Android
  • MacOS
  • IOS
  • Other Platforms

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@dkalinowski
Copy link
Author

Is this vulnerability going to be resolved?

@KaibaLopez
Copy link
Contributor

Hi, sorry for the late update, but yes, this has been merged thanks for the PR.

@KaibaLopez KaibaLopez closed this Jul 8, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Outdated version of cJSON used by aws-cpp-sdk-core contains security vulnerabilities
2 participants