not-going-to-be-commons-ssl icon indicating copy to clipboard operation
not-going-to-be-commons-ssl copied to clipboard

Don't depend on version 3.1 of commons-httpclient

Open bwf93 opened this issue 5 years ago • 2 comments

commons-httpclient version 3.1 has several known vulnerabilities. The artifact is renamed for 4.x and should be used instead

bwf93 avatar Dec 10 '19 17:12 bwf93

Aye aye! I'll try to make some time in the near future to address this and some of the other issues!

narupley avatar Dec 10 '19 18:12 narupley

I second the request. If it helps at all, the main issue you'll have with migrating will be with the HttpSecureProtocol class as the SecureProtocolSocketFactory class has been completely removed. I don't see anything resembling an alternative to it.

gthazmatt avatar Dec 20 '19 22:12 gthazmatt