Skip to content

Old http client library with known vulnerability used in implementation #286

@encapsecurity

Description

@encapsecurity

The library pulls in commons-httpclient 3.1 which has a known vulnerability making it possible to spoof SSL servers, see https://access.redhat.com/security/cve/CVE-2012-5783 for details. Should be replaced with something that does not have a known vulnerability. (e.g org.apache.httpcomponents:httpclient)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions