You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@jackrabbit.apache.org by "Julian Reschke (Jira)" <ji...@apache.org> on 2019/12/18 12:40:00 UTC

[jira] [Closed] (JCR-3912) Jackrabbit depends on obsolete commons-httpclient library

     [ https://issues.apache.org/jira/browse/JCR-3912?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Julian Reschke closed JCR-3912.
-------------------------------

> Jackrabbit depends on obsolete commons-httpclient library
> ---------------------------------------------------------
>
>                 Key: JCR-3912
>                 URL: https://issues.apache.org/jira/browse/JCR-3912
>             Project: Jackrabbit Content Repository
>          Issue Type: Bug
>          Components: security
>    Affects Versions: 2.10.1, 2.11.0
>         Environment: Debian GNU/Linux
>            Reporter: Markus Koschany
>            Priority: Major
>              Labels: security
>
> Hello,
> jackrabbit depends on commons-httpclient. https://hc.apache.org/httpclient-3.x/
> This library has reached EOL status four years ago and was replaced by Apache httpcomponents-client:
> https://hc.apache.org/httpcomponents-client-ga/index.html
> commons-httpclient was affected by multiple security issues in the past but is no longer supported by its upstream developers. This makes it difficult for Linux distributions to provide any support for applications and libraries which still depend on commons-httpclient.
> Please consider to make the switch to httpcomponents-client



--
This message was sent by Atlassian Jira
(v8.3.4#803005)