Details
-
Task
-
Resolution: Fixed
-
Major
-
13.7-rc-1
-
None
Description
See http://x-stream.github.io/changes.html#1.4.20 (from 1.4.17)
XStream moved to a white list system making its default pretty much unusable for jobs status, we'll need to check how we can workaround that. Another possibility being to move to another system but unless we can find one with the exact same format it can be a breaking change (impossible to read already serialized job status and more importantly break some job REST calls).
Attachments
Issue Links
- is duplicated by
-
XCOMMONS-2541 CVE-2022-40151 because of XStream
- Closed
-
XCOMMONS-1222 Find a workaround for new XStream (1.4.10) security framework limitation
- Closed
-
XWIKI-21052 Check the CVEs for xstream
- Closed