lavalink-devs / lavaplayer

Lavaplayer fork maintained by Lavalink
Apache License 2.0
187 stars 51 forks source link

Transitive vulnerability through json 20230618 library #112

Closed LeonardoPantani closed 6 months ago

LeonardoPantani commented 6 months ago

As stated in the title, importing this library via Maven triggers a transitive vulnerability warning due to the maven:org.json:json:20230618 library (CVE-2023-5072 7.5 Allocation of Resources Without Limits or Throttling vulnerability with High severity found).