From 191cc407cac86afe6633ddf44de3c37166fd318f Mon Sep 17 00:00:00 2001 From: PJ Fanning Date: Wed, 30 Nov 2022 02:07:24 +0100 Subject: [PATCH] xstream 1.4.19 (fixes a CVE) (#1472) --- eureka-client/build.gradle | 2 +- eureka-core/build.gradle | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/eureka-client/build.gradle b/eureka-client/build.gradle index af9dfdceb7..a6e556b4a3 100644 --- a/eureka-client/build.gradle +++ b/eureka-client/build.gradle @@ -7,7 +7,7 @@ configurations.all { dependencies { compile "com.netflix.netflix-commons:netflix-eventbus:0.3.0" - compile 'com.thoughtworks.xstream:xstream:1.4.18' + compile 'com.thoughtworks.xstream:xstream:1.4.19' compile "com.netflix.archaius:archaius-core:${archaiusVersion}" compile 'javax.ws.rs:jsr311-api:1.1.1' compile "com.netflix.servo:servo-core:${servoVersion}" diff --git a/eureka-core/build.gradle b/eureka-core/build.gradle index 8fb3fe1e15..32b69cfd63 100644 --- a/eureka-core/build.gradle +++ b/eureka-core/build.gradle @@ -7,7 +7,7 @@ dependencies { compile "com.amazonaws:aws-java-sdk-sts:${awsVersion}" compile "com.amazonaws:aws-java-sdk-route53:${awsVersion}" compile "javax.servlet:servlet-api:${servletVersion}" - compile 'com.thoughtworks.xstream:xstream:1.4.17' + compile 'com.thoughtworks.xstream:xstream:1.4.19' compile 'javax.ws.rs:jsr311-api:1.1.1' // These dependencies are marked 'compileOnly' in the client, but we need them always on the server