qinlonglong123 opened a new issue, #4843:
URL: https://github.com/apache/servicecomb-java-chassis/issues/4843

   ### Steps to reproduce (if applicable)
   
   
   > Uncontrolled Resource Consumption vulnerability in Apache Commons 
Configuration 1.x. There are a number of issues in Apache Commons Configuration 
1.x that allow excessive resource consumption when loading untrusted 
configurations or using unexpected usage patterns. The Apache Commons 
Configuration team does not intend to fix these issues in 1.x. Apache Commons 
Configuration 1.x is still safe to use in scenario's where you only load 
trusted configurations. Users that load untrusted configurations or give 
attackers control over usage patterns are recommended to upgrade to the 2.x 
version line, which fixes these issues. Apache Commons Configuration 2.x is not 
a drop-in replacement, but as it uses a separate Maven groupId and Java package 
namespace they can be loaded side-by-side, making it possible to do a gradual 
migration.
   
   
   ### What have you tried so far?
   
   升级依赖软件Apache Commons Configuration到2.x
   
   ### Additional context
   
   _No response_


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to