eclipse-ee4j / eclipse-ee4j/metro-xmlstreambuffer

Vulnerability in xmlstreambuffer dependency - CVE-2022-40152

Open
#71 0 comments 1 reaction 0 assignees View on GitHub
Dominant language
Java
Stars
1
Forks
4
PR merge metrics
No merged PRs in 30d

Description

I see that we have a high severity vulnerability CVE-2022-40152 in the latest version of streambuffer - 2.1.0 which was released in 2022. But I see that there was a commit named "**[Bump woodstox-core from 6.2.8 to 6.4.0 in /streambuffer](https://github.com/eclipse-ee4j/metro-xmlstreambuffer/commit/1fdfbc5f14c3dbe5cb2f5be00199ec26e1f65597)"** where the respective vulnerability has been fixed by upgrading the woodstox-core library from 6.2.8 to 6.4.0, but it was never packaged with release.

Can we have a release package with this vulnerability fix ?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.