[ https://issues.apache.org/jira/browse/WW-5167?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Lukasz Lenart resolved WW-5167. ------------------------------- Resolution: Fixed > Upgrade XStream to version 1.4.19 > --------------------------------- > > Key: WW-5167 > URL: https://issues.apache.org/jira/browse/WW-5167 > Project: Struts 2 > Issue Type: Dependency > Reporter: Lukasz Lenart > Priority: Trivial > Fix For: 2.6 > > > This maintenance release addresses the security vulnerability CVE-2021-43859, > when unmarshalling highly recursive collections or maps causing a Denial of > Service. > http://x-stream.github.io/CVE-2021-43859.html -- This message was sent by Atlassian Jira (v8.20.1#820001)