-
Task
-
Resolution: Done
-
Neutral
-
POMs 41
-
None
-
-
Empty show more show less
-
Empty show more show less
-
Maintenance 50
-
1
CVE scan identified more vulnerabilities in Magnolia DX Core webapp related to xstream.
xstream-1.4.15.jar (pkg:maven/com.thoughtworks.xstream/xstream@1.4.15, cpe:2.3:a:xstream_project:xstream:1.4.15:*:*:*:*:*:*:*) : CVE-2021-21341, CVE-2021-21342, CVE-2021-21343, CVE-2021-21344, CVE-2021-21345, CVE-2021-21346, CVE-2021-21347, CVE-2021-21348, CVE-2021-21349, CVE-2021-21350, CVE-2021-21351
xstream is pulled in via info.magnolia.workflow:magnolia-module-workflow-jbpm -> ... -> org.jbpm:jbpm-flow and is not used directly by Magnolia as it was determined by DEV-1689
I would therefore dismiss CVE warnings regarding it from now on. Let's rather consider updating jbpm libraries in workflow instead.
Acceptance criteria