Skip to content

Apache HttpClient vulnerability #104

Description

@mgorovoy

We use Snyk to notify us of vulnerabilities in the OSS dependencies of our product. We recently received a report about CVE-2020-13956. We determined that the transitive dependency to Apache HttpClient 4.5.12 in our product comes via the GoogleAuth project (below). In order to rectify this issue, this dependency needs to be updated to version 4.5.14.

[INFO] +- com.warrenstrange:googleauth:jar:1.5.0:compile
[INFO] | - org.apache.httpcomponents:httpclient:jar:4.5.12:compile
[INFO] | - org.apache.httpcomponents:httpcore:jar:4.4.16:compile

Furthermore, it is extremely confusing that the releases on GitHub page and releases in Maven Central are not synchronized. It would be great if it was possible to backfill release 1.3-1.5 and release the latest changes as 1.6 at your convenience.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions