From 0815ea2689080197e91044cd79f97cdd0e48fa0d Mon Sep 17 00:00:00 2001 From: Derek Ho Date: Mon, 16 Oct 2023 15:37:16 -0400 Subject: [PATCH] Upgrade JSON to 20231013 to fix CVE-2023-5072 Signed-off-by: Derek Ho --- build.gradle | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/build.gradle b/build.gradle index 5d69bd4d..9de0d9df 100644 --- a/build.gradle +++ b/build.gradle @@ -174,7 +174,7 @@ dependencies { implementation "org.jetbrains.kotlinx:kotlinx-coroutines-core:1.3.9" implementation "${group}:common-utils:${common_utils_version}" compileOnly "${group}:opensearch-job-scheduler-spi:${job_scheduler_version}" - implementation "org.json:json:20230227" + implementation "org.json:json:20231013" implementation group: 'com.github.wnameless.json', name: 'json-flattener', version: '0.15.1' // json-base, jackson-databind, jackson-annotations are transitive dependencies by json-flattener implementation group: 'com.github.wnameless.json', name: 'json-base', version: '2.2.1'