clj-commons / aleph

Asynchronous streaming communication for Clojure - web server, web client, and raw TCP/UDP
http://aleph.io
MIT License
2.54k stars 241 forks source link

Please bump netty versions because of CVE-2023-34462 #684

Closed svdo closed 1 year ago

svdo commented 1 year ago

Apparently there is a new vulnerability in netty that has been fixed in 4.1.94.Final. Could you perhaps release a new version of aleph with the new netty version? Thank you! More information at https://github.com/advisories/GHSA-6mjq-h674-j845.

KingMob commented 1 year ago

Fixed in 0.6.3.