[
https://issues.apache.org/jira/browse/HADOOP-19335?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17902983#comment-17902983
]
ASF GitHub Bot commented on HADOOP-19335:
-----------------------------------------
pjfanning commented on PR #7158:
URL: https://github.com/apache/hadoop/pull/7158#issuecomment-2517204458
@steveloughran I think having to update them together might be the exception
as opposed to the rule. In this case, the newer version of netty did affect the
old version of grpc-java but there have been many upgrades to netty that didn't
impact grpc-java.
> Bump netty to 4.1.115 due to CVE-2024-47535
> -------------------------------------------
>
> Key: HADOOP-19335
> URL: https://issues.apache.org/jira/browse/HADOOP-19335
> Project: Hadoop Common
> Issue Type: Task
> Reporter: PJ Fanning
> Priority: Major
> Labels: pull-request-available
>
> https://nvd.nist.gov/vuln/detail/CVE-2024-47535
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]