Nikolay Krasko created WAGON-612: ------------------------------------ Summary: Update jsoup to >= 1.14.2 for fix security issue Key: WAGON-612 URL: https://issues.apache.org/jira/browse/WAGON-612 Project: Maven Wagon Issue Type: Dependency upgrade Components: wagon-http Affects Versions: 3.4.3 Reporter: Nikolay Krasko
There's a vulnerability report for the jsoup <= 1.14.2 [https://www.cvedetails.com/cve/CVE-2021-37714|https://www.cvedetails.com/cve/CVE-2021-37714/] jsoup:1.12.1 is used by wagon-http-shared:3.4.3, that triggers security bots alerts. Please could you update the dependency and release a new version? -- This message was sent by Atlassian Jira (v8.3.4#803005)