-
Bug
-
Resolution: Done
-
Major
-
fuse-7.11.1-GA
For CVE-2020-13956, the Red Hat Fuse Spring-Boot 2 BOM is including commons-httpclient/commons-httpclient/3.1.0.redhat-8 as part of io.hawt/hawtio-springboot/2.0.0.fuse-sb2-7_11_0-00036-redhat-00001
+- io.hawt:hawtio-springboot:jar:2.0.0.fuse-sb2-7_11_0-00036-redhat-00001:compile +- io.hawt:hawtio-system:jar:2.0.0.fuse-sb2-7_11_0-00036-redhat-00001:compile +- commons-httpclient:commons-httpclient:jar:3.1.0.redhat-8:compile