conductor-oss / conductor-oss/clojure-sdk

[GHSA-vr64-r9qj-h27f] org.clojure:clojure@1.10.3: Deserialization infinite loop

Open
#8 1 comment 0 reactions 0 assignees View on GitHub
security vulnerability
Dominant language
Clojure
Stars
23
Forks
0
PR merge metrics
No merged PRs in 30d

Description

## Vulnerability Details

- **Advisory:** [GHSA-vr64-r9qj-h27f](https://github.com/advisories/GHSA-vr64-r9qj-h27f)
- **Package:** `org.clojure:clojure`
- **Current Version:** 1.10.3
- **Fixed Version:** 1.12.0
- **Severity:** Reading specially crafted serializable objects from an untrusted source may cause an infinite loop

## Description

The current `deps.edn` declares a dependency on `org.clojure/clojure` version `1.10.3`, which is affected by GHSA-vr64-r9qj-h27f. This vulnerability allows an attacker to cause an infinite loop by providing specially crafted serializable objects to be read from an untrusted source.

## Recommended Fix

Bump `org.clojure/clojure` from `1.10.3` to `1.12.0` (latest stable release) in `deps.edn`.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.