Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to Xstream 1.4.11.1 due to reopening of vulnerability CVE-2013-7285 #1222

Closed
ankurbhakta opened this issue Jun 27, 2019 · 3 comments · Fixed by #1223
Closed

Upgrade to Xstream 1.4.11.1 due to reopening of vulnerability CVE-2013-7285 #1222

ankurbhakta opened this issue Jun 27, 2019 · 3 comments · Fixed by #1223

Comments

@ankurbhakta
Copy link

Looks like the old vulnerability in CVE-2013-7284 was not fully addressed by Xstream version 1.4.10. This old version is showing up in our vulnerability scans. Can we upgrade to the newer xstream version 1.4.11.1

Links to release notes/vulnerability fixes:
https://x-stream.github.io/changes.html

@mattnelson
Copy link
Contributor

Another option is to completely remove xstream as proposed in #1074

@spencergibb
Copy link
Contributor

I agree with @mattnelson #1074 would be the long term fix, this one being a quick easy fix.

@troshko111
Copy link
Contributor

Thanks for the report @ankurbhakta and the PR @spencergibb, appreciate it. No emotional attachment to Xstream but we do not want to break anyone so any solution will need to be compatible.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants