json-rules-engine
json-rules-engine copied to clipboard
High severity security flaw in JSONPath Plus allows Remote Code Execution - please update dependency
High severity security flaw in JSONPath Plus allows Remote Code Execution - please update dependency
This vulnerability is preventing my team from deploying into production: https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-8719585. As stated above, please update jsonpath-plus to 10.3.0.
It has been resolved in this PR but yet to be merged.
I see that this has been merged and 7.3.1 is now on NPM.
Thanks to @danish-khan-I and @chris-pardy
Thank you for the quick response!