Package
tez
Component
async-http-client
Latest update
Fixed version
0.10.4-r8
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
0.10.4-r8Status
Status
Fixed version
0.10.4-r6Status
Impact
This vulnerability relates to async-http-client, and a fix exists in v2.12.4 and later. Attempts to bump this have resulted in build failures. Additonally, there is an upstream dependabot PR to resolve, which is also failing:
Status