This is an automated email from the ASF dual-hosted git repository.

stevel pushed a commit to branch trunk
in repository https://gitbox.apache.org/repos/asf/hadoop.git


The following commit(s) were added to refs/heads/trunk by this push:
     new bbf905dc99bb HADOOP-18933. upgrade to netty 4.1.100 due to CVE (#6173)
bbf905dc99bb is described below

commit bbf905dc99bb8939f61bcb25fe158f56cc826352
Author: PJ Fanning <pjfann...@users.noreply.github.com>
AuthorDate: Wed Oct 25 14:06:13 2023 +0100

    HADOOP-18933. upgrade to netty 4.1.100 due to CVE (#6173)
    
    
    Mitigates Netty security advisory GHSA-xpw8-rcwv-8f8p
    "HTTP/2 Rapid Reset Attack - DDoS vector in the HTTP/2 protocol due RST 
frames"
    
    Contributed by PJ Fanning
---
 LICENSE-binary         | 60 +++++++++++++++++++++++++-------------------------
 hadoop-project/pom.xml |  2 +-
 2 files changed, 31 insertions(+), 31 deletions(-)

diff --git a/LICENSE-binary b/LICENSE-binary
index c367abdff574..e2f61dc7cd84 100644
--- a/LICENSE-binary
+++ b/LICENSE-binary
@@ -257,36 +257,36 @@ io.grpc:grpc-netty:1.26.0
 io.grpc:grpc-protobuf:1.26.0
 io.grpc:grpc-protobuf-lite:1.26.0
 io.grpc:grpc-stub:1.26.0
-io.netty:netty-all:4.1.94.Final
-io.netty:netty-buffer:4.1.94.Final
-io.netty:netty-codec:4.1.94.Final
-io.netty:netty-codec-dns:4.1.94.Final
-io.netty:netty-codec-haproxy:4.1.94.Final
-io.netty:netty-codec-http:4.1.94.Final
-io.netty:netty-codec-http2:4.1.94.Final
-io.netty:netty-codec-memcache:4.1.94.Final
-io.netty:netty-codec-mqtt:4.1.94.Final
-io.netty:netty-codec-redis:4.1.94.Final
-io.netty:netty-codec-smtp:4.1.94.Final
-io.netty:netty-codec-socks:4.1.94.Final
-io.netty:netty-codec-stomp:4.1.94.Final
-io.netty:netty-codec-xml:4.1.94.Final
-io.netty:netty-common:4.1.94.Final
-io.netty:netty-handler:4.1.94.Final
-io.netty:netty-handler-proxy:4.1.94.Final
-io.netty:netty-resolver:4.1.94.Final
-io.netty:netty-resolver-dns:4.1.94.Final
-io.netty:netty-transport:4.1.94.Final
-io.netty:netty-transport-rxtx:4.1.94.Final
-io.netty:netty-transport-sctp:4.1.94.Final
-io.netty:netty-transport-udt:4.1.94.Final
-io.netty:netty-transport-classes-epoll:4.1.94.Final
-io.netty:netty-transport-native-unix-common:4.1.94.Final
-io.netty:netty-transport-classes-kqueue:4.1.94.Final
-io.netty:netty-resolver-dns-classes-macos:4.1.94.Final
-io.netty:netty-transport-native-epoll:4.1.94.Final
-io.netty:netty-transport-native-kqueue:4.1.94.Final
-io.netty:netty-resolver-dns-native-macos:4.1.94.Final
+io.netty:netty-all:4.1.100.Final
+io.netty:netty-buffer:4.1.100.Final
+io.netty:netty-codec:4.1.100.Final
+io.netty:netty-codec-dns:4.1.100.Final
+io.netty:netty-codec-haproxy:4.1.100.Final
+io.netty:netty-codec-http:4.1.100.Final
+io.netty:netty-codec-http2:4.1.100.Final
+io.netty:netty-codec-memcache:4.1.100.Final
+io.netty:netty-codec-mqtt:4.1.100.Final
+io.netty:netty-codec-redis:4.1.100.Final
+io.netty:netty-codec-smtp:4.1.100.Final
+io.netty:netty-codec-socks:4.1.100.Final
+io.netty:netty-codec-stomp:4.1.100.Final
+io.netty:netty-codec-xml:4.1.100.Final
+io.netty:netty-common:4.1.100.Final
+io.netty:netty-handler:4.1.100.Final
+io.netty:netty-handler-proxy:4.1.100.Final
+io.netty:netty-resolver:4.1.100.Final
+io.netty:netty-resolver-dns:4.1.100.Final
+io.netty:netty-transport:4.1.100.Final
+io.netty:netty-transport-rxtx:4.1.100.Final
+io.netty:netty-transport-sctp:4.1.100.Final
+io.netty:netty-transport-udt:4.1.100.Final
+io.netty:netty-transport-classes-epoll:4.1.100.Final
+io.netty:netty-transport-native-unix-common:4.1.100.Final
+io.netty:netty-transport-classes-kqueue:4.1.100.Final
+io.netty:netty-resolver-dns-classes-macos:4.1.100.Final
+io.netty:netty-transport-native-epoll:4.1.100.Final
+io.netty:netty-transport-native-kqueue:4.1.100.Final
+io.netty:netty-resolver-dns-native-macos:4.1.100.Final
 io.opencensus:opencensus-api:0.12.3
 io.opencensus:opencensus-contrib-grpc-metrics:0.12.3
 io.reactivex:rxjava:1.3.8
diff --git a/hadoop-project/pom.xml b/hadoop-project/pom.xml
index 9303d7ff4c80..25e48f293a64 100644
--- a/hadoop-project/pom.xml
+++ b/hadoop-project/pom.xml
@@ -143,7 +143,7 @@
     <jna.version>5.2.0</jna.version>
     <gson.version>2.9.0</gson.version>
     <metrics.version>3.2.4</metrics.version>
-    <netty4.version>4.1.94.Final</netty4.version>
+    <netty4.version>4.1.100.Final</netty4.version>
     <snappy-java.version>1.1.10.4</snappy-java.version>
     <lz4-java.version>1.7.1</lz4-java.version>
 


---------------------------------------------------------------------
To unsubscribe, e-mail: common-commits-unsubscr...@hadoop.apache.org
For additional commands, e-mail: common-commits-h...@hadoop.apache.org

Reply via email to