Skip to content

Conversation

@JonathanSmithSkipton
Copy link

@JonathanSmithSkipton JonathanSmithSkipton commented Sep 11, 2025

Description

Followup fix for vulnerability CVE-2024-21534 previous addressed in #3369

See: https://nvd.nist.gov/vuln/detail/CVE-2025-1302

Pre-merge checklist

This is for use by the Artillery team. Please leave this in if you're contributing to Artillery.

  • Does this require an update to the docs?
  • Does this require a changelog entry?

@CLAassistant
Copy link

CLAassistant commented Sep 11, 2025

CLA assistant check
All committers have signed the CLA.

@JonathanSmithSkipton JonathanSmithSkipton changed the title fix: update jsonpath-plus to recommended 10.3.0 fix: update jsonpath-plus for CVE-2025-1302 Sep 11, 2025
@JonathanSmithSkipton
Copy link
Author

@hassy anything you need from me on this? very interested in getting this RCE vulnerability closed off from a security point of view

@JonathanSmithSkipton
Copy link
Author

@hassy do we have an eta on when this would likely be merged? getting alot of alerts raised from this due to its nature as a critical vulnerability

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants