This is an automated email from the ASF dual-hosted git repository. stevel pushed a commit to branch branch-3.3 in repository https://gitbox.apache.org/repos/asf/hadoop.git
The following commit(s) were added to refs/heads/branch-3.3 by this push: new 1708df37fb1b HADOOP-18933. upgrade to netty 4.1.100 due to CVE (#6173) 1708df37fb1b is described below commit 1708df37fb1b86cd9470e9e7025199596333dd81 Author: PJ Fanning <pjfann...@users.noreply.github.com> AuthorDate: Thu Nov 2 18:01:47 2023 +0000 HADOOP-18933. upgrade to netty 4.1.100 due to CVE (#6173) Mitigates Netty security advisory GHSA-xpw8-rcwv-8f8p "HTTP/2 Rapid Reset Attack - DDoS vector in the HTTP/2 protocol due RST frames" Contributed by PJ Fanning --- LICENSE-binary | 60 +++++++++++++++++++++++++------------------------- hadoop-project/pom.xml | 2 +- 2 files changed, 31 insertions(+), 31 deletions(-) diff --git a/LICENSE-binary b/LICENSE-binary index 68105f4cbe92..8a0186374c38 100644 --- a/LICENSE-binary +++ b/LICENSE-binary @@ -263,36 +263,36 @@ io.grpc:grpc-protobuf:1.26.0 io.grpc:grpc-protobuf-lite:1.26.0 io.grpc:grpc-stub:1.26.0 io.netty:netty:3.10.6.Final -io.netty:netty-all:4.1.77.Final -io.netty:netty-buffer:4.1.77.Final -io.netty:netty-codec:4.1.77.Final -io.netty:netty-codec-dns:4.1.77.Final -io.netty:netty-codec-haproxy:4.1.77.Final -io.netty:netty-codec-http:4.1.77.Final -io.netty:netty-codec-http2:4.1.77.Final -io.netty:netty-codec-memcache:4.1.77.Final -io.netty:netty-codec-mqtt:4.1.77.Final -io.netty:netty-codec-redis:4.1.77.Final -io.netty:netty-codec-smtp:4.1.77.Final -io.netty:netty-codec-socks:4.1.77.Final -io.netty:netty-codec-stomp:4.1.77.Final -io.netty:netty-codec-xml:4.1.77.Final -io.netty:netty-common:4.1.77.Final -io.netty:netty-handler:4.1.77.Final -io.netty:netty-handler-proxy:4.1.77.Final -io.netty:netty-resolver:4.1.77.Final -io.netty:netty-resolver-dns:4.1.77.Final -io.netty:netty-transport:4.1.77.Final -io.netty:netty-transport-rxtx:4.1.77.Final -io.netty:netty-transport-sctp:4.1.77.Final -io.netty:netty-transport-udt:4.1.77.Final -io.netty:netty-transport-classes-epoll:4.1.77.Final -io.netty:netty-transport-native-unix-common:4.1.77.Final -io.netty:netty-transport-classes-kqueue:4.1.77.Final -io.netty:netty-resolver-dns-classes-macos:4.1.77.Final -io.netty:netty-transport-native-epoll:4.1.77.Final -io.netty:netty-transport-native-kqueue:4.1.77.Final -io.netty:netty-resolver-dns-native-macos:4.1.77.Final +io.netty:netty-all:4.1.100.Final +io.netty:netty-buffer:4.1.100.Final +io.netty:netty-codec:4.1.100.Final +io.netty:netty-codec-dns:4.1.100.Final +io.netty:netty-codec-haproxy:4.1.100.Final +io.netty:netty-codec-http:4.1.100.Final +io.netty:netty-codec-http2:4.1.100.Final +io.netty:netty-codec-memcache:4.1.100.Final +io.netty:netty-codec-mqtt:4.1.100.Final +io.netty:netty-codec-redis:4.1.100.Final +io.netty:netty-codec-smtp:4.1.100.Final +io.netty:netty-codec-socks:4.1.100.Final +io.netty:netty-codec-stomp:4.1.100.Final +io.netty:netty-codec-xml:4.1.100.Final +io.netty:netty-common:4.1.100.Final +io.netty:netty-handler:4.1.100.Final +io.netty:netty-handler-proxy:4.1.100.Final +io.netty:netty-resolver:4.1.100.Final +io.netty:netty-resolver-dns:4.1.100.Final +io.netty:netty-transport:4.1.100.Final +io.netty:netty-transport-rxtx:4.1.100.Final +io.netty:netty-transport-sctp:4.1.100.Final +io.netty:netty-transport-udt:4.1.100.Final +io.netty:netty-transport-classes-epoll:4.1.100.Final +io.netty:netty-transport-native-unix-common:4.1.100.Final +io.netty:netty-transport-classes-kqueue:4.1.100.Final +io.netty:netty-resolver-dns-classes-macos:4.1.100.Final +io.netty:netty-transport-native-epoll:4.1.100.Final +io.netty:netty-transport-native-kqueue:4.1.100.Final +io.netty:netty-resolver-dns-native-macos:4.1.100.Final io.opencensus:opencensus-api:0.12.3 io.opencensus:opencensus-contrib-grpc-metrics:0.12.3 io.reactivex:rxjava:1.3.8 diff --git a/hadoop-project/pom.xml b/hadoop-project/pom.xml index f89df0e6ff69..75a4b9c496a0 100644 --- a/hadoop-project/pom.xml +++ b/hadoop-project/pom.xml @@ -148,7 +148,7 @@ <gson.version>2.9.0</gson.version> <metrics.version>3.2.4</metrics.version> <netty3.version>3.10.6.Final</netty3.version> - <netty4.version>4.1.89.Final</netty4.version> + <netty4.version>4.1.100.Final</netty4.version> <snappy-java.version>1.1.10.4</snappy-java.version> <lz4-java.version>1.7.1</lz4-java.version> --------------------------------------------------------------------- To unsubscribe, e-mail: common-commits-unsubscr...@hadoop.apache.org For additional commands, e-mail: common-commits-h...@hadoop.apache.org