mockserver
mockserver copied to clipboard
Is this project dead?
There has been no releases since 2023. Maven and others are reporting about security problems. So is this project dead and if so what are people moving to? WireMock?
Today we had a security incident reported that the latest docker image from docker hub is doing dns querys to www.litecoinpool.org. I highly recommend not using mockserver anymore.
Today we had a security incident reported that the latest docker image from docker hub is doing dns querys to www.litecoinpool.org. I highly recommend not using mockserver anymore.
Hey @simon-eon,
thanks for sharing this! Can you talk about how you detected the questionable dns queries and on what platform? So far I could not see those dns queries with wireshark (on macOS with Docker Desktop and mockserver/mockserver:5.15.0).
Today we had a security incident reported that the latest docker image from docker hub is doing dns querys to www.litecoinpool.org. I highly recommend not using mockserver anymore.
Hey @simon-eon,
thanks for sharing this! Can you talk about how you detected the questionable dns queries and on what platform? So far I could not see those dns queries with wireshark (on macOS with Docker Desktop and mockserver/mockserver:5.15.0).
It's probably due to latest; 5.15.0 has different digest. But I didn't check latest with wireshark myself.
Duplicate of https://github.com/mock-server/mockserver/issues/1912