**What is the bug?** https://advisories.opensearch.org/advisories/CVE-2024-57699 introduced by `json-smart.jar` ``` +--- org.apache.calcite:calcite-core:1.38.0 | +--- com.jayway.jsonpath:json-path:2.9.0 | | +--- net.minidev:json-smart:2.5.0 ```