You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@maven.apache.org by "Sylwester Lachiewicz (JIRA)" <ji...@apache.org> on 2017/11/24 18:28:00 UTC

[jira] [Created] (MNG-6312) Update Maven Wagon dependency

Sylwester Lachiewicz created MNG-6312:
-----------------------------------------

             Summary: Update Maven Wagon dependency
                 Key: MNG-6312
                 URL: https://issues.apache.org/jira/browse/MNG-6312
             Project: Maven
          Issue Type: Dependency upgrade
            Reporter: Sylwester Lachiewicz


Based on OWASP report - update Maven Wagon from 2.12 to 3.0.0 to fix known vulnerability in shaded jsoup

wagon-http-2.12-shaded.jar\META-INF/maven/org.jsoup/jsoup/pom.xml (cpe:/a:jsoup:jsoup:1.7.2, org.jsoup:jsoup:1.7.2) : CVE-2015-6748




--
This message was sent by Atlassian JIRA
(v6.4.14#64029)