[ https://issues.apache.org/jira/browse/WW-5329?focusedWorklogId=874015&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-874015 ]
ASF GitHub Bot logged work on WW-5329: -------------------------------------- Author: ASF GitHub Bot Created on: 01/Aug/23 10:41 Start Date: 01/Aug/23 10:41 Worklog Time Spent: 10m Work Description: lukaszlenart merged PR #721: URL: https://github.com/apache/struts/pull/721 Issue Time Tracking ------------------- Worklog Id: (was: 874015) Time Spent: 0.5h (was: 20m) > Upgrade xstream to version 1.4.20 > --------------------------------- > > Key: WW-5329 > URL: https://issues.apache.org/jira/browse/WW-5329 > Project: Struts 2 > Issue Type: Dependency > Components: Core > Reporter: Lukasz Lenart > Priority: Major > Fix For: 6.3.0 > > Time Spent: 0.5h > Remaining Estimate: 0h > > This maintenance release addresses the security vulnerabilities > CVE-2022-40151 and CVE-2022-41966, causing a Denial of Service by raising a > stack overflow. It also provides new converters for Optional and Atomic types. -- This message was sent by Atlassian Jira (v8.20.10#820010)