eclipse-ee4j / eclipse-ee4j/metro-xmlstreambuffer
Vulnerability in xmlstreambuffer dependency - CVE-2022-40152
Open
- Dominant language
- Java
- Stars
- 1
- Forks
- 4
- PR merge metrics
- No merged PRs in 30d
Description
I see that we have a high severity vulnerability CVE-2022-40152 in the latest version of streambuffer - 2.1.0 which was released in 2022. But I see that there was a commit named "**[Bump woodstox-core from 6.2.8 to 6.4.0 in /streambuffer](https://github.com/eclipse-ee4j/metro-xmlstreambuffer/commit/1fdfbc5f14c3dbe5cb2f5be00199ec26e1f65597)"** where the respective vulnerability has been fixed by upgrading the woodstox-core library from 6.2.8 to 6.4.0, but it was never packaged with release.
Can we have a release package with this vulnerability fix ?
Contributor guide
Assessment
This issue has not been assessed yet.