CyberSource / cybersource-sdk-java

Java SDK for CyberSource Simple Order API
Other
51 stars 84 forks source link

Bump xalan to 2.7.3 #174

Open bmiller-0 opened 10 months ago

bmiller-0 commented 10 months ago

Cybersource imports xalan-2.7.2.jar, which has a vulnerability noted in CVE-2022-34169 https://nvd.nist.gov/vuln/detail/CVE-2022-34169

The issue is fixed in xalan-2.7.3. Would like to see if cybersource could be updated accordingly