Netflix / eureka

AWS Service registry for resilient mid-tier load balancing and failover.
Apache License 2.0
12.39k stars 3.74k forks source link

High Severity Vulnerability in xstream-1.4.19.jar #1483

Open gdut-yy opened 1 year ago

gdut-yy commented 1 year ago

December 24, 2022 XStream 1.4.20 released

This maintenance release addresses the security vulnerabilities CVE-2022-40151 and CVE-2022-41966, causing a Denial of Service by raising a stack overflow. It also provides new converters for Optional and Atomic types.

shyamrox commented 1 year ago

I just submitted this fix. Feel free to assign the issue to me so I can close it out once the pull request is merged. https://github.com/Netflix/eureka/pull/1516