Don't depend on version 3.1 of commons-httpclient
Opened this issue · 2 comments
bwf93 commented
commons-httpclient version 3.1 has several known vulnerabilities. The artifact is renamed for 4.x and should be used instead
narupley commented
Aye aye! I'll try to make some time in the near future to address this and some of the other issues!
gthazmatt commented
I second the request. If it helps at all, the main issue you'll have with migrating will be with the HttpSecureProtocol class as the SecureProtocolSocketFactory class has been completely removed. I don't see anything resembling an alternative to it.