We know it's fastjson, since it's part of what splunk offers, splunk might consider on doing something on it. I don't think anyone is advocating for a "no thinking" approach or remediation for the sake of making a scanner report look green. The intent is to understand whether the finding is applicable, assess the actual risk, and then determine the appropriate action. If the risk turns out to be negligible or not applicable to our use case, that's a valid outcome of the assessment as well. The vulnerability scanner is simply highlighting an area that warrants review, not dictating the final decision.
... View more