confluentinc / ksql-images

KSQL platform docker images
Apache License 2.0
7 stars 21 forks source link

chore: Upgrade netty to 4.1.100.Final for CVE-2023-44487 #105

Closed tzulitai closed 1 year ago

tzulitai commented 1 year ago

This PR upgrades netty to 4.1.00.Final and netty-tcnative-version to 2.0.61.Final to address https://nvd.nist.gov/vuln/detail/CVE-2023-44487.

4.1.100.Final address the vulnerability according to https://netty.io/news/2023/10/10/4-1-100-Final.html.

also: https://github.com/confluentinc/ksql/pull/10080

cla-assistant[bot] commented 1 year ago

CLA assistant check
All committers have signed the CLA.