[
https://issues.apache.org/jira/browse/ZOOKEEPER-4209?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Frederiko Costa updated ZOOKEEPER-4209:
---------------------------------------
Fix Version/s: (was: 3.4.6)
(was: 3.5.0)
3.5.10
Affects Version/s: (was: 3.4.5)
3.5.9
Description:
Zookeeper 3.5.9 upgraded netty to 4.1.50.Final. Would like to uptake netty
4.1.53.Final which addressed the vulnerability described at
[https://snyk.io/vuln/SNYK-JAVA-IONETTY-1020439]
was:
Upgrade netty version
Environment: It appears this is an issue that affects all versions,
as this has only been address on netty 4.1.53.Final, which hasn't been up-taken
yet (last upgrade afaict was 4.1.50.Final) (was: zookeeper 3.4.5 uses netty
3.2.2, which was released in August 2010. The latest version of netty is 3.6.6
released May 2013. Zookeeper should consider upgrading.)
> Upgrade netty version to 4.1.53.Final
> -------------------------------------
>
> Key: ZOOKEEPER-4209
> URL: https://issues.apache.org/jira/browse/ZOOKEEPER-4209
> Project: ZooKeeper
> Issue Type: Improvement
> Affects Versions: 3.5.9
> Environment: It appears this is an issue that affects all versions,
> as this has only been address on netty 4.1.53.Final, which hasn't been
> up-taken yet (last upgrade afaict was 4.1.50.Final)
> Reporter: Frederiko Costa
> Assignee: Sean Bridges
> Priority: Major
> Fix For: 3.5.10
>
>
> Zookeeper 3.5.9 upgraded netty to 4.1.50.Final. Would like to uptake netty
> 4.1.53.Final which addressed the vulnerability described at
> [https://snyk.io/vuln/SNYK-JAVA-IONETTY-1020439]
>
--
This message was sent by Atlassian Jira
(v8.3.4#803005)