Nikolay Krasko created WAGON-612:
------------------------------------

             Summary: Update jsoup to >= 1.14.2 for fix security issue
                 Key: WAGON-612
                 URL: https://issues.apache.org/jira/browse/WAGON-612
             Project: Maven Wagon
          Issue Type: Dependency upgrade
          Components: wagon-http
    Affects Versions: 3.4.3
            Reporter: Nikolay Krasko


There's a vulnerability report for the jsoup <= 1.14.2 
[https://www.cvedetails.com/cve/CVE-2021-37714|https://www.cvedetails.com/cve/CVE-2021-37714/]

jsoup:1.12.1 is used by wagon-http-shared:3.4.3, that triggers security bots 
alerts. 

Please could you update the dependency and release a new version?




--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to