Package
zaproxy
Component
httpclient5
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The CVE GHSA-hjcp-jmpx-g3qm (httpclient5 < 5.6.3) is the result of a pre-built binary plugin that is downloaded at build time from the ZAP plugin repository, not built from the zaproxy source code. As a result, there is no dependency we can bump to remediate. The fix requires an upstream release of the ZAP network plugin with the appropriate dependency upgraded.
Status