Uploaded image for project: 'Cache Modules'
  1. Cache Modules
  2. MGNLCACHE-299

Replace json-io with gson

    XMLWordPrintable

Details

    • Task
    • Resolution: Unresolved
    • Neutral
    • None
    • 6.0.0, 5.9.6
    • cache browser
    • None

    Description

      Recently a vulnerability against json-io was reported. Although not exploitable in Magnolia's case, the cache browser app uses the potentially vulnerable API (JsonReader.jsonToJava) at https://git.magnolia-cms.com/projects/MODULES/repos/cache/browse/magnolia-cache-browser-app/src/main/java/info/magnolia/cache/browser/rest/endpoint/CacheEndpoint.java#219.

      As json-io seems to be poorly maintained, it would be good to replace it with Google's gson.

      Checklists

        Acceptance criteria

        Attachments

          Issue Links

            Activity

              People

                Unassigned Unassigned
                fgrilli Federico Grilli
                DeveloperX
                Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                  Created:
                  Updated:

                  Checklists

                    Task DoR