Details
-
Bug
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
1.7.0, 1.7.1
-
None
Description
Hi
Request for removal of dependency of commons-httpclient 3.1 on Apache Axis2, as this version of httpclient bundled in axis2-1.7.1 is exposed to to the vulnerability CVE-2012-6153, CVE-2014-3577
The Vulnerability says that the class "http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3" is vulnerability. (https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-6153)
Additional information on these vulnerabilities can be found at these links:
https://exchange.xforce.ibmcloud.com/vulnerabilities/95327
https://exchange.xforce.ibmcloud.com/vulnerabilities/95328
http://archives.neohapsis.com/archives/bugtraq/2014-08/0089.html
Dependency of commons-httpclient-3.1.jar should be upgraded to the newer GA versions available (https://hc.apache.org/downloads.cgi)
Regds,
Deepak