Uploaded image for project: 'Maven Help Plugin'
  1. Maven Help Plugin
  2. MPH-196

Bump xstream to 1.4.20

    XMLWordPrintableJSON

Details

    • Dependency upgrade
    • Status: Closed
    • Trivial
    • Resolution: Fixed
    • None
    • 3.4.0
    • None
    • None

    Description

      https://x-stream.github.io/changes.html

       

      This maintenance release addresses the security vulnerabilities CVE-2022-40151 and CVE-2022-41966, causing a Denial of Service by raising a stack overflow. It also provides new converters for Optional and Atomic types.

      Note, the next major release 1.5 will require Java 11.

      Attachments

        Issue Links

          Activity

            People

              slachiewicz Sylwester Lachiewicz
              slachiewicz Sylwester Lachiewicz
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: