xstream:1.4.20 has vulnerability:

to fix the issue upgrade to xstream:1.4.21