Mate Szalay-Beko created ZOOKEEPER-4543:
-------------------------------------------

             Summary: upgrade dependencies on branch-3.5 to avoid CVEs
                 Key: ZOOKEEPER-4543
                 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-4543
             Project: ZooKeeper
          Issue Type: Bug
    Affects Versions: 3.5.9
            Reporter: Mate Szalay-Beko
            Assignee: Mate Szalay-Beko
             Fix For: 3.5.10


The aim of this ticket to fix all CVEs on branch-3.5 before the last 3.5.10 
release. 

branch-3.5 is quite outdated when it comes to CVE fixes. I already backported
ZOOKEEPER-4455 (remove log4j and add reload4j) but other dependencies are also 
outdated. Most probably the dependency plugin also needs to be updated  to 
avoid the netty-transport related false-positive CVEs.
 
 



--
This message was sent by Atlassian Jira
(v8.20.7#820007)

Reply via email to