Mate Szalay-Beko created ZOOKEEPER-4543: -------------------------------------------
Summary: upgrade dependencies on branch-3.5 to avoid CVEs Key: ZOOKEEPER-4543 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-4543 Project: ZooKeeper Issue Type: Bug Affects Versions: 3.5.9 Reporter: Mate Szalay-Beko Assignee: Mate Szalay-Beko Fix For: 3.5.10 The aim of this ticket to fix all CVEs on branch-3.5 before the last 3.5.10 release. branch-3.5 is quite outdated when it comes to CVE fixes. I already backported ZOOKEEPER-4455 (remove log4j and add reload4j) but other dependencies are also outdated. Most probably the dependency plugin also needs to be updated to avoid the netty-transport related false-positive CVEs. -- This message was sent by Atlassian Jira (v8.20.7#820007)