Skip to content

Newtonsoft.JSON not showing CVE-2024-21907 in the vulnerability report  #6789

@bsuchorowskiandea

Description

@bsuchorowskiandea

Describe the bug
We don't see any vulnerability in the report for Newtonsoft.JSON 12.0.3

Version of dependency-check used
Dependency-Check Core version 10.0.1

Log file

dotnet build results:
Warning NU1903: Package 'Newtonsoft.Json' 12.0.3 has a known high severity vulnerability,
GHSA-5crp-9r3c-p9vr

OWASP:
no results

Expected behavior
Vulnerability should be visible. To my best knowledge it is published in NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-21907

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions