AzureAD / azure-activedirectory-library-for-java

MIT License
161 stars 126 forks source link

CVE Issue in ADAL4j's oauth2-oidc-sdk dependency #310

Closed g2vinay closed 2 years ago

g2vinay commented 2 years ago

The oauth2-oidc-sdk:9.4 being used by adal4j has the following vulnerability coming in from json-smart dependency.

The adal4j library needs to update the oauth2-oidc-sdk to version 9.20 (the latest) that has this CVE issue resolved.

This issue is impacting our customers. Let us know as soon as the patch release is out with updated dependencies.