intuit / QuickBooks-V3-Java-SDK

Java SDK for QuickBooks REST API v3 services
Apache License 2.0
70 stars 144 forks source link

Bump gson to latest 2.11.0 due to vulnerability in 2.8.1 #217

Open rhamedyvena opened 5 months ago

rhamedyvena commented 5 months ago

The gson version 2.8.1 has some vulnerabilities

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25647 and https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250

and it's recommended to update to the latest 2.11.0