[
https://issues.apache.org/jira/browse/CASSANDRA-17368?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17489736#comment-17489736
]
Brandon Williams commented on CASSANDRA-17368:
----------------------------------------------
I think since these are harmless we can add suppressions for 3.0, 3.11, and
4.0. For trunk, we can upgrade netty-all to 4.1.73.Final.
||Branch||CI||
|[3.0|https://github.com/driftx/cassandra/tree/CASSANDRA-17368-3.0]|[j8|https://app.circleci.com/pipelines/github/driftx/cassandra/351/workflows/1d7c9315-6dd2-4963-9adf-f61379ecd179]|
|[3.11|https://github.com/driftx/cassandra/tree/CASSANDRA-17368-3.11]|[J8|https://app.circleci.com/pipelines/github/driftx/cassandra/352/workflows/21aa6b59-09cc-4042-8a94-0b0a561408a9]|
|[4.0|https://github.com/driftx/cassandra/tree/CASSANDRA-17368-4.0]|[j8|https://app.circleci.com/pipelines/github/driftx/cassandra/353/workflows/634c0cf4-9d13-48f3-88df-b75e3df51d50]|
|[trunk|https://github.com/driftx/cassandra/tree/CASSANDRA-17368-trunk]|[j8|https://app.circleci.com/pipelines/github/driftx/cassandra/350/workflows/a7d3828f-3d35-4c01-b673-bed9319ad21b],
[j11|https://app.circleci.com/pipelines/github/driftx/cassandra/350/workflows/6c707186-df54-4200-9a69-783bbc4f21bd]|
> Investigate OWASP failure report
> --------------------------------
>
> Key: CASSANDRA-17368
> URL: https://issues.apache.org/jira/browse/CASSANDRA-17368
> Project: Cassandra
> Issue Type: Bug
> Components: Build
> Reporter: Brandon Williams
> Assignee: Brandon Williams
> Priority: Normal
>
> 4.0: netty-all-4.1.58.Final.jar: CVE-2021-43797, CVE-2021-37136,
> CVE-2021-37137
> 3.11: netty-all-4.0.44.Final.jar: CVE-2021-43797, CVE-2021-37136,
> CVE-2021-37137
> 3.0: netty-all-4.0.44.Final.jar: CVE-2021-43797, CVE-2021-37136,
> CVE-2021-37137
--
This message was sent by Atlassian Jira
(v8.20.1#820001)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]