{"id":"GHSA-fjh6-p566-wr6q","summary":"skylot jadx affected by Incorrect Behavior Order in vulnerable dependency","details":"### Impact\nVulnerable library protobuf-java 3.11.4 (CVE-2021-22569)\n\n### Patches\nDependency updated in jadx 1.4.3\n\n### References\nAccording to the AquaSecurity report:\n![05F1C52A666E4FCC844ABD085BD55124](https://user-images.githubusercontent.com/118523/177364939-087e2144-9a8a-4594-ae90-eb2acb0a2036.png)\n\nAlso, Maven repository have links to this and other vulnerabilities from dependencies:\nhttps://mvnrepository.com/artifact/com.google.protobuf/protobuf-java/3.11.4","modified":"2024-11-28T05:41:28.895550Z","published":"2022-07-21T22:35:12Z","database_specific":{"cwe_ids":["CWE-696"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-07-21T22:35:12Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/skylot/jadx/security/advisories/GHSA-fjh6-p566-wr6q"},{"type":"PACKAGE","url":"https://github.com/skylot/jadx"},{"type":"WEB","url":"https://github.com/skylot/jadx/releases/tag/v1.4.3"}],"affected":[{"package":{"name":"io.github.skylot:jadx-core","ecosystem":"Maven","purl":"pkg:maven/io.github.skylot/jadx-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.3"}]}],"versions":["1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.4.0","1.4.1","1.4.2"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.4.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-fjh6-p566-wr6q/GHSA-fjh6-p566-wr6q.json"}}],"schema_version":"1.9.0"}