CyberSource / cybersource-sdk-java

Java SDK for CyberSource Simple Order API
Other
51 stars 84 forks source link

Arbitrary code execution vulnerability #169

Open kennyfundrise opened 1 year ago

kennyfundrise commented 1 year ago

Received this vulnerability report via Snyk: https://security.snyk.io/vuln/SNYK-JAVA-XALAN-2953385

Cybersource imports Xalan, all versions of Xalan are affected. Would be helpful to confirm that Cybersource SDK is not affected by this vulnerability or to patch it.

bmiller-0 commented 10 months ago

Suggest bumping xalan to 2.7.3