[ 
https://issues.apache.org/jira/browse/CASSANDRA-17697?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17559282#comment-17559282
 ] 

Josh McKenzie commented on CASSANDRA-17697:
-------------------------------------------

[CI Results]
Branch: 4.1, build number: 77
   butler url: 
https://butler.cassandra.apache.org/#/ci/upstream/compare/Cassandra-4.1/Cassandra-4.1
   jenkins url: https://ci-cassandra.apache.org/job/Cassandra-4.1/77/
   JIRA: CASSANDRA-17697
   commit url: 
https://gitbox.apache.org/repos/asf?p=cassandra.git;a=commit;h=5ed63e0a5a01bf7709bb5adc9165ccc6e6d9a7cf
   affected paths:
* CHANGES.txt
* .build/dependency-check-suppressions.xml

   Build Result: UNSTABLE
   Passing Tests: 46788
   Failing Tests: 13

||Test|Failures|JIRA||
|org.apache.cassandra.cql3.validation.operations.SelectTest.testIndexQueryWithCompositePartitionKey|3
 of 74|[No JIRA 
found|https://issues.apache.org/jira/secure/RapidBoard.jspa?rapidView=496&quickFilter=2252]
|org.apache.cassandra.distributed.upgrade.CompactStoragePagingTest.testPagingWithCompactStorage|5
 of 74|[No JIRA 
found|https://issues.apache.org/jira/secure/RapidBoard.jspa?rapidView=496&quickFilter=2252]
|org.apache.cassandra.distributed.test.SchemaTest.readRepairWithCompaction|20 
of 74|[CASSANDRA-17641?|https://issues.apache.org/jira/browse/CASSANDRA-17641]|
|org.apache.cassandra.cql3.validation.entities.SecondaryIndexTest.testIndexOnClusteringKeyInsertExpiringColumn|5
 of 74|[No JIRA 
found|https://issues.apache.org/jira/secure/RapidBoard.jspa?rapidView=496&quickFilter=2252]
|org.apache.cassandra.distributed.upgrade.BatchUpgradeTest.batchTest|22 of 
74|[CASSANDRA-17651?|https://issues.apache.org/jira/browse/CASSANDRA-17651]|
|org.apache.cassandra.cql3.validation.entities.SecondaryIndexTest.testIndexesOnComplexPrimaryKey|7
 of 74|[No JIRA 
found|https://issues.apache.org/jira/secure/RapidBoard.jspa?rapidView=496&quickFilter=2252]
|org.apache.cassandra.tools.TopPartitionsTest.testServiceTopPartitionsSingleTable|7
 of 74|[CASSANDRA-17649?|https://issues.apache.org/jira/browse/CASSANDRA-17649]|
|org.apache.cassandra.net.ConnectionTest.testMessageDeliveryOnReconnect|4 of 
74|[CASSANDRA-16677?|https://issues.apache.org/jira/browse/CASSANDRA-16677]|
|org.apache.cassandra.cql3.ViewComplexUpdatesTest.testUpdateWithColumnTimestampSmallerThanPkWithFlush[3]|2
 of 74|[No JIRA 
found|https://issues.apache.org/jira/secure/RapidBoard.jspa?rapidView=496&quickFilter=2252]
|org.apache.cassandra.cql3.validation.entities.SecondaryIndexTest.testCanQuerySecondaryIndex|5
 of 74|[No JIRA 
found|https://issues.apache.org/jira/secure/RapidBoard.jspa?rapidView=496&quickFilter=2252]
|org.apache.cassandra.cql3.ViewComplexTTLTest.testBaseTTLWithSameTimestampTest[3]|2
 of 74|[No JIRA 
found|https://issues.apache.org/jira/secure/RapidBoard.jspa?rapidView=496&quickFilter=2252]
|org.apache.cassandra.cql3.validation.operations.SelectTest.testTokenFctRejectsInvalidColumnCount|2
 of 74|[No JIRA 
found|https://issues.apache.org/jira/secure/RapidBoard.jspa?rapidView=496&quickFilter=2252]
|org.apache.cassandra.db.commitlog.CommitLogSegmentManagerCDCTest.testSegmentFlaggingWithNonblockingOnCreation|4
 of 74|[CASSANDRA-17542?|https://issues.apache.org/jira/browse/CASSANDRA-17542]|


> netty-all 4.0.44 is affected by CVE-2020-7238
> ---------------------------------------------
>
>                 Key: CASSANDRA-17697
>                 URL: https://issues.apache.org/jira/browse/CASSANDRA-17697
>             Project: Cassandra
>          Issue Type: Bug
>          Components: Dependencies
>            Reporter: Brandon Williams
>            Assignee: Brandon Williams
>            Priority: Normal
>             Fix For: 3.0.28, 3.11.14
>
>
> {noformat}
> Dependency-Check Failure:
> One or more dependencies were identified with vulnerabilities that have a 
> CVSS score greater than or equal to '1.0': 
> netty-all-4.0.44.Final.jar: CVE-2020-7238
> {noformat}
> Similar to CASSANDRA-17633, the HTTP request smuggling vulnerabilities 
> continue.



--
This message was sent by Atlassian Jira
(v8.20.7#820007)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to