-
Terminally Deprecated Elements
-
Deprecated ClassesClassDescriptionsince 7.2.0, scheduled for removal in a future major version. XStream has a long history of deserialization vulnerabilities and requires per-class allowlist maintenance. The default
xmlbinding instruts-plugin.xmlusesJacksonXmlHandler, which respects@StrutsParameterauthorization via theAuthorizationAwareContentTypeHandlermechanism. Users who have explicitly overridden thexmlhandler toXStreamHandlershould migrate toJacksonXmlHandler.
xmlbinding instruts-plugin.xmlusesJacksonXmlHandler, which respects@StrutsParameterauthorization via theAuthorizationAwareContentTypeHandlermechanism. Users who have explicitly overridden thexmlhandler toXStreamHandlershould migrate toJacksonXmlHandler.