Skip to content

2.35.1 - Security Release

Compare
Choose a tag to compare
@oleg-nenashev oleg-nenashev released this 06 Sep 18:08
· 881 commits to master since this release

🔒 This is a security release that addresses the following issues

NOTE: WireMock Studio, a proprietary distribution discontinued in 2022, is also affected by those issues and also affected by CVE-2023-39967 - Overall CVSS Score 8.6 - “Controlled and full-read SSRF through URL parameter when testing a request, webhooks and proxy mode”. The fixes will not be provided. The vendor recommends migrating to WireMock Cloud which is available as SaaS and private beta for on-premises deployments

Credits: @W0rty, @numacanedo, @Mahoney, @tomakehurst, @oleg-nenashev