Skip to content

CVE vulnerabilities found in dependent packages: jackson-coreutils and json-patch #196

Description

@Danny-TU

Description

First of all, thank you for your continuous efforts in making Keycloak the leading identity solution.

While reviewing the dependency tree for keycloak-admin-client (v26.x), I noticed that it currently maintains dependencies on the following artifacts:

jackson-coreutils 2.0: https://mvnrepository.com/artifact/com.github.java-json-tools/jackson-coreutils/2.0

json-patch 1.13: https://mvnrepository.com/artifact/com.github.fge/json-patch/1.13

According to the security information provided in the repositories, these specific versions are reported to contain multiple known vulnerabilities.

Discussion

No response

Motivation

When integrating Keycloak into applications with high security requirements, these dependencies are frequently flagged due to the presence of multiple CVEs. It would be beneficial to transition to a more secure implementation.

Details

Are there any plans or a roadmap to migrate the JSON Patch/Pointer logic to a more secure implementation?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions