Open
Description
The latest Microsoft.Azure.CognitiveServices.Vision.ComputerVision version is 7.0.1 which has a Newtonsoft.Json dependency that uses v10.0.3 which is vulnerable
I'm running a SAST scan that recommends to update Newtonsoft.Json to v13.0.1 but the dev team can't make this update
How can I mitigate this vulnerability?
Metadata
Metadata
Assignees
Labels
This issue points to a problem in the data-plane of the library.Workflow: This issue is responsible by Azure service team.Issues that are reported by GitHub users external to the Azure organization.Workflow: This issue needs attention from Azure service team or SDK teamThe issue doesn't require a change to the product in order to be resolved. Most issues start as that