Skip to content

Upgrade to Netty 4.1.115.Final to address CVE-2024-47535#4524

Merged
hezhangjian merged 1 commit into
apache:masterfrom
lhotari:lh-netty-4.1.115
Nov 19, 2024
Merged

Upgrade to Netty 4.1.115.Final to address CVE-2024-47535#4524
hezhangjian merged 1 commit into
apache:masterfrom
lhotari:lh-netty-4.1.115

Conversation

@lhotari

@lhotari lhotari commented Nov 13, 2024

Copy link
Copy Markdown
Member

Motivation

Upgrade to Netty 4.1.115.Final to address CVE-2024-47535. This DoS vulnerability doesn't practically apply to BookKeeper since the vulnerability requires write access to the filesystem where the application using Netty is running. However, it's always useful to address CVEs by upgrading to a version that doesn't contain known vulnerabilities.

Changes

@hezhangjian
hezhangjian merged commit d873ca4 into apache:master Nov 19, 2024
lhotari added a commit that referenced this pull request Apr 16, 2025
lhotari added a commit that referenced this pull request Apr 16, 2025
manas-ctds pushed a commit to datastax/bookkeeper that referenced this pull request Feb 27, 2026
(cherry picked from commit d873ca4)
(cherry picked from commit 48bcef7)
dlg99 pushed a commit to datastax/bookkeeper that referenced this pull request Feb 27, 2026
(cherry picked from commit d873ca4)
(cherry picked from commit 48bcef7)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants