You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@zookeeper.apache.org by "Mate Szalay-Beko (Jira)" <ji...@apache.org> on 2022/05/17 12:00:00 UTC
[jira] [Created] (ZOOKEEPER-4543) upgrade dependencies on branch-3.5 to avoid CVEs
Mate Szalay-Beko created ZOOKEEPER-4543:
-------------------------------------------
Summary: upgrade dependencies on branch-3.5 to avoid CVEs
Key: ZOOKEEPER-4543
URL: https://issues.apache.org/jira/browse/ZOOKEEPER-4543
Project: ZooKeeper
Issue Type: Bug
Affects Versions: 3.5.9
Reporter: Mate Szalay-Beko
Assignee: Mate Szalay-Beko
Fix For: 3.5.10
The aim of this ticket to fix all CVEs on branch-3.5 before the last 3.5.10 release.
branch-3.5 is quite outdated when it comes to CVE fixes. I already backported
ZOOKEEPER-4455 (remove log4j and add reload4j) but other dependencies are also outdated. Most probably the dependency plugin also needs to be updated to avoid the netty-transport related false-positive CVEs.
--
This message was sent by Atlassian Jira
(v8.20.7#820007)