[
https://issues.apache.org/jira/browse/ZOOKEEPER-4417?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Anil Kumar Ravva updated ZOOKEEPER-4417:
----------------------------------------
Description:
Netty related jars have downgraded in latest(3.7.0) to lower version compared
the previous versions of zookeeper(3.6.3).
Please find the details below:
Current Zookeeper Version 3.7.0: netty 4.1.59 version jars have been used
Old Zookeeper version apache-zookeeper-3.6.3 : netty 4.1.63 have been used.
Is there any reason behind this change?
There are so many security advances have been made as part of netty upgrade,
All those were missed here.
Is there any plan of adding this jar in the future release.
was:
Netty related jars have downgraded in latest(3.7.0) to lower version compared
the previous versions of zookeeper(3.6.3).
Please find the details below:
Current Zookeeper Version 3.7.0: netty 4.1.59 version jars have been used
Old Zookeeper version apache-zookeeper-3.6.3 : netty 4.1.63 have been used.
Is there any reason behind this change?
There are so many security advances have been made as part of netty upgrade,
All those were missed here.
> Zookeeper 3.7.0 : Netty related jars to be upgraded to 4.1.68 for Security
> upgrade
> ----------------------------------------------------------------------------------
>
> Key: ZOOKEEPER-4417
> URL: https://issues.apache.org/jira/browse/ZOOKEEPER-4417
> Project: ZooKeeper
> Issue Type: Bug
> Components: server
> Affects Versions: 3.7.0
> Reporter: Anil Kumar Ravva
> Priority: Critical
>
> Netty related jars have downgraded in latest(3.7.0) to lower version compared
> the previous versions of zookeeper(3.6.3).
> Please find the details below:
> Current Zookeeper Version 3.7.0: netty 4.1.59 version jars have been used
> Old Zookeeper version apache-zookeeper-3.6.3 : netty 4.1.63 have been used.
> Is there any reason behind this change?
> There are so many security advances have been made as part of netty upgrade,
> All those were missed here.
>
> Is there any plan of adding this jar in the future release.
--
This message was sent by Atlassian Jira
(v8.20.1#820001)