Uploaded image for project: 'Jackrabbit Content Repository'
  1. Jackrabbit Content Repository
  2. JCR-3912

Jackrabbit depends on obsolete commons-httpclient library

    XMLWordPrintableJSON

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Major
    • Resolution: Duplicate
    • Affects Version/s: 2.10.1, 2.11.0
    • Fix Version/s: None
    • Component/s: security
    • Labels:
    • Environment:
      Debian GNU/Linux

      Description

      Hello,

      jackrabbit depends on commons-httpclient. https://hc.apache.org/httpclient-3.x/

      This library has reached EOL status four years ago and was replaced by Apache httpcomponents-client:

      https://hc.apache.org/httpcomponents-client-ga/index.html

      commons-httpclient was affected by multiple security issues in the past but is no longer supported by its upstream developers. This makes it difficult for Linux distributions to provide any support for applications and libraries which still depend on commons-httpclient.

      Please consider to make the switch to httpcomponents-client

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                Unassigned
                Reporter:
                apo Markus Koschany
              • Votes:
                0 Vote for this issue
                Watchers:
                3 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: