fix CVE-2021-27568

Comment From: snicoll

@strehle thanks for the PR but as indicated in the template, we prefer to do such dependency upgrades ourselves. In the meantime you can override the version of json-path using the json-path.version.