Details
-
Improvement
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
3.4.0
-
Reviewed
Description
An issue was discovered in json-io 4.14.0 that allows attackers to cause a denial of service via crafted object that uses cyclic dependencies. de.ruedigermoeller:fst only imports java-util (and through that json-io) as a test dependency, so I think we can safely add an exclusion for it.
Attachments
Issue Links
- links to