[ https://issues.apache.org/jira/browse/DOXIA-615?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Michael Osipov updated DOXIA-615: --------------------------------- Summary: Upgrade HttpClient to 4.5.13 (was: Can you provide an updated version in order to fix CVE-2020-13956) > Upgrade HttpClient to 4.5.13 > ---------------------------- > > Key: DOXIA-615 > URL: https://issues.apache.org/jira/browse/DOXIA-615 > Project: Maven Doxia > Issue Type: Dependency upgrade > Components: Core > Affects Versions: 1.6, 1.9.1 > Reporter: Philipp Ottlinger > Assignee: Elliotte Rusty Harold > Priority: Major > Fix For: 1.10 > > > [https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEHTTPCOMPONENTS-1016906] > [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13956] > Over at RAT we do use doxia-core and just got a security report (RAT-275) > that doxia uses a problematic version of httpclient. > Can you update to a more recent version and provide a new release? > Thanks -- This message was sent by Atlassian Jira (v8.3.4#803005)