nazrulworld / fhir.resources

FHIR Resources https://www.hl7.org/fhir/resourcelist.html
https://pypi.org/project/fhir.resources/
Other
365 stars 104 forks source link

Security vulnerability in orjson package: CVE-2024-27454 #154

Open jvanschie opened 3 months ago

jvanschie commented 3 months ago

Description

According to https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27454 there is a security vulnerability in package: orjson. I don't know if this vulnerability is really impacted through the code, but it seems that it can be easily fixed by upgrading the orjson package to a version newer than 3.9.15. Could you please update this package so we can remove this vulnerability from our ignore list :)? Thanks in advance.

What I Did

Scan for security vulnerabilities with the [safety](https://docs.safetycli.com/safety-docs) tool.