exasol / extension-manager

Exasol extension-manager
MIT License
2 stars 0 forks source link

Fix CVE-2024-29025 in `io.netty:netty-codec-http:jar:4.1.107.Final:runtime` #172

Closed kaklakariada closed 6 months ago

kaklakariada commented 7 months ago

Also workflow https://github.com/exasol/extension-manager/actions/runs/8516433491/job/23325446695 fails.

Error:  Failed to execute goal org.sonatype.ossindex.maven:ossindex-maven-plugin:3.2.0:audit (audit) on project extension-manager-integration-test-java: Detected 1 vulnerable components:
Error:    io.netty:netty-codec-http:jar:4.1.107.Final:runtime; https://ossindex.sonatype.org/component/pkg:maven/io.netty/netty-codec-http@4.1.107.Final?utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1
Error:      * [CVE-2024-29025] CWE-770: Allocation of Resources Without Limits or Throttling (5.3); https://ossindex.sonatype.org/vulnerability/CVE-2024-29025?component-type=maven&component-name=io.netty%2Fnetty-codec-http&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1
Error:  -> [Help 1]