Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Upgrade xstream-1.4.19 to 1.4.20 for CVE-2022-40151 and CVE-2022-41966. #1482

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

gdut-yy
Copy link
Contributor

@gdut-yy gdut-yy commented Jan 7, 2023

https://x-stream.github.io/news.html

December 24, 2022 XStream 1.4.20 released

This maintenance release addresses the security vulnerabilities CVE-2022-40151 and CVE-2022-41966, causing a Denial of Service by raising a stack overflow. It also provides new converters for Optional and Atomic types.

@gdut-yy
Copy link
Contributor Author

gdut-yy commented Jan 7, 2023

#1483

@sullis
Copy link
Contributor

sullis commented Mar 6, 2023

cc: @alexburnos

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants