[ https://issues.apache.org/jira/browse/FALCON-1979?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Balu Vellanki updated FALCON-1979: ---------------------------------- Issue Type: Improvement (was: Bug) > Update HttpClient versions to close security vulnerabilities > ------------------------------------------------------------ > > Key: FALCON-1979 > URL: https://issues.apache.org/jira/browse/FALCON-1979 > Project: Falcon > Issue Type: Improvement > Reporter: Balu Vellanki > Assignee: Balu Vellanki > Fix For: trunk, 0.10 > > > We learned that > https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-5262 : > http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents > HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting > during an SSL handshake, which allows remote attackers to cause a denial of > service (HTTPS call hang) via unspecified vectors. > Hence, HttpClient version should be updated. -- This message was sent by Atlassian JIRA (v6.3.4#6332)