Details
-
Bug
-
Resolution: Fixed
-
Major
-
16.10.13
-
None
Description
Apache HTTP Client 3 is exposed publicly in XWiki#getHttpClient which is both wrong in general and made even worst because this library has a serious vulnerability.