Nikolay Krasko created WAGON-612:
------------------------------------
Summary: Update jsoup to >= 1.14.2 for fix security issue
Key: WAGON-612
URL: https://issues.apache.org/jira/browse/WAGON-612
Project: Maven Wagon
Issue Type: Dependency upgrade
Components: wagon-http
Affects Versions: 3.4.3
Reporter: Nikolay Krasko
There's a vulnerability report for the jsoup <= 1.14.2
[https://www.cvedetails.com/cve/CVE-2021-37714|https://www.cvedetails.com/cve/CVE-2021-37714/]
jsoup:1.12.1 is used by wagon-http-shared:3.4.3, that triggers security bots
alerts.
Please could you update the dependency and release a new version?
--
This message was sent by Atlassian Jira
(v8.3.4#803005)