Skip to content

Conversation

@jmini
Copy link
Contributor

@jmini jmini commented Jan 9, 2025

A CVE was reported against org.asynchttpclient:async-http-client 2.12.3

  • Vulnerability: CVE-2024-53990
  • Fixed Version: 2.12.4, 3.0.1
  • Title: async-http-client: AsyncHttpClient (AHC) library's CookieStore replaces explicitly defined Cookies

See:

This pull request is updating the library to version 2.12.4

@martijndwars martijndwars merged commit 9ea7e2a into web-push-libs:master Feb 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants