[
https://issues.apache.org/jira/browse/CASSANDRA-15153?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17413549#comment-17413549
]
Michael Semb Wever commented on CASSANDRA-15153:
------------------------------------------------
bq. Are we good to go with the latest Caffeine version? Alternatively, we can
use a hybrid approach - update old versions to 2.5.0 (the first version where
the problem seems to be fixed) and 4.1 to 3.0.3 (the latest version) - if that
seems to be safer.
This makes sense. In older versions we need to check there's no performance
impacts (via testing or code reviewing) .
> Caffeine cache return stale entries
> -----------------------------------
>
> Key: CASSANDRA-15153
> URL: https://issues.apache.org/jira/browse/CASSANDRA-15153
> Project: Cassandra
> Issue Type: Bug
> Components: Feature/Authorization
> Reporter: Per Otterström
> Assignee: Aleksei Zotov
> Priority: Normal
> Labels: security
>
> Version 2.3.5 of the Caffeine cache that we're using in various places can
> hand out stale entries in some cases. This seem to happen when an update
> fails repeatedly, in which case Caffeine may return a previously loaded
> value. For instance, the AuthCache may hand out permissions even though the
> reload operation is failing, see CASSANDRA-15041.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]