The following is the result of the vulnerability scan that we have performed on WebClient version 1.8.8-pre13079.
We have scanned for vulnerabilities using the most current OWASP dependency check in the log4j version that is used in WebClient. We found two vulnerabilities that do not affect WebClient as WebClient does not use SockerServer and SMTP/SMTPS.
1. CVE-2019-17571
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
2. CVE-2020-9488
CWE-295 Improper Certificate Validation
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender.
Please contact us at support if you have any questions about this statement.