Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Apache Commons codec 1.11 dependency is having a vulnerability due to which Restassured is caught by BlackDuck and other scans. #1725

Open
pvchaitu opened this issue Sep 4, 2023 · 2 comments

Comments

@pvchaitu
Copy link

pvchaitu commented Sep 4, 2023

Apache Commons codec 1.11 dependency is having a vulnerability due to which Restassured is caught by BlackDuck and other scans to have vulnerability.

This is the issue in current latest Restassured library 5.3.1 version. Curious when the next release is coming up and if the Commons-codec dependency is going to be upgraded to latest version?

@gruenich
Copy link

Apache Commons codec 1.11 is a dependency of Apache httpclient 4.5. It was droppen by the switch to httpclient5. I expect that MR #1719 will fix this issue. @pvchaitu, can you confirm?

@pvchaitu
Copy link
Author

Yes, HttpClient5 (5.2.1) should take care of the issue and has no vulnerabilities as of today. Please also see if you can bump up below dependencies:
johnzon-mapper to 1.2.21 or later
jackson-mapper-asl to 2.15.2 or later

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants