Details
-
Fix
-
Status: Released (View Workflow)
-
Minor
-
Resolution: Fixed
-
1.13.9
-
None
-
CVE-2020-13956
Description
Current Situation
- Currently JobScheduler components use org.apache.httpcomponents:httpclient version 4.5.2
- a vulnerability affects this version,
Desired Behavior
- Due to a vulnerability Issue of older httpcomponents:httpclient releases the JobScheduler components should use the current version 4.5.13 that fixes the issues.