Skip to content

Consider upgrading vulnerable version of java-websocket #731

@lalvarezguillen

Description

@lalvarezguillen

There's a security advisory against java-websocket<=1.4.1: https://nvd.nist.gov/vuln/detail/CVE-2020-11050

ably-java is using java-websocket:1.4.0. I couldn't find an issue mentioning this CVE, so I'm creating the issue to document and consider upgrading.

┆Issue is synchronized with this Jira Bug by Unito

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working. It's clear that this does need to be fixed.

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions