From 50db5d24a7c45375c0b32fffa238256276e6432e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=BC=A0=E9=80=B8=E6=89=AC?= <33390928+gdut-yy@users.noreply.github.com> Date: Thu, 1 Apr 2021 01:52:07 +0800 Subject: [PATCH] Upgrade xstream to 1.4.16 for CVE-2021-213{41-51} (#1386) --- eureka-client/build.gradle | 2 +- eureka-core/build.gradle | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/eureka-client/build.gradle b/eureka-client/build.gradle index fe02a3450..92e55ad07 100644 --- a/eureka-client/build.gradle +++ b/eureka-client/build.gradle @@ -7,7 +7,7 @@ configurations.all { dependencies { compile "com.netflix.netflix-commons:netflix-eventbus:0.3.0" - compile 'com.thoughtworks.xstream:xstream:1.4.15' + compile 'com.thoughtworks.xstream:xstream:1.4.16' compile "com.netflix.archaius:archaius-core:${archaiusVersion}" compile 'javax.ws.rs:jsr311-api:1.1.1' compile "com.netflix.servo:servo-core:${servoVersion}" diff --git a/eureka-core/build.gradle b/eureka-core/build.gradle index 276f73dd0..ff76b61dc 100644 --- a/eureka-core/build.gradle +++ b/eureka-core/build.gradle @@ -7,7 +7,7 @@ dependencies { compile "com.amazonaws:aws-java-sdk-sts:${awsVersion}" compile "com.amazonaws:aws-java-sdk-route53:${awsVersion}" compile "javax.servlet:servlet-api:${servletVersion}" - compile 'com.thoughtworks.xstream:xstream:1.4.15' + compile 'com.thoughtworks.xstream:xstream:1.4.16' compile 'javax.ws.rs:jsr311-api:1.1.1' // These dependencies are marked 'compileOnly' in the client, but we need them always on the server