Bugzilla – Bug 1218034
VUL-0: CVE-2023-50246: jq: Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.
Last modified: 2024-05-15 14:06:26 UTC
jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-50246
References: https://github.com/jqlang/jq/security/advisories/GHSA-686w-5m7m-54vc https://github.com/jqlang/jq/commit/71c2ab509a8628dbbad4bc7b3f98a64aa90d3297
SLE (12 and 15) are on jq 1.6, so this bug is valid for Factory only.
openSUSE:Factory is not affected by this issue, as it contains version 1.7.1 of package jq, which is already fixed for this issue.