Anne Yu created SENTRY-1446:
-------------------------------

             Summary: Upgrade httpmime (Sentry) to 4.3.6 or greater.
                 Key: SENTRY-1446
                 URL: https://issues.apache.org/jira/browse/SENTRY-1446
             Project: Sentry
          Issue Type: New Feature
          Components: Sentry
    Affects Versions: 1.8.0
            Reporter: Anne Yu
            Assignee: Anne Yu
             Fix For: 1.8.0


http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents 
HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting 
during an SSL handshake, which allows remote attackers to cause a denial of 
service (HTTPS call hang) via unspecified vectors.
Upgrade to 4.3.6 or greater.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to