Skip to content

Remove dep on sec vuln: software.amazon.ion:ion-java:1.0.2

High
ALRubinger published GHSA-g6qj-pj38-2465 Feb 28, 2024

Package

maven software.amazon.ion:ion-java (Maven)

Affected versions

1.0.2

Patched versions

com.amazon.ion:ion-java:1.10.5+

Description

Sec Vuln discovered 3 days ago in:
https://github.com/TBD54566975/web5-kt/actions/runs/8054648142/job/21999680974

We can resolve via upgrading the package which brings in an older, vulnerable software.amazon.ion:ion-java, com.amazonaws:aws-java-sdk-kms, to 1.12.668, which doesn't have this dependency. Note that software.amazon.ion:ion-java has been moved in groupId to com.amazon.ion:ion-java. But this upgrade removes the dep entirely.

Addressed upstream in c314311

Severity

High

CVE ID

CVE-2024-21634

Weaknesses

No CWEs