Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability in Netty 4.1.45 via Cassandra java-driver-core 4.6.1 #2400

Closed
patriknw opened this issue Sep 10, 2020 · 1 comment · Fixed by #2416
Closed

Security vulnerability in Netty 4.1.45 via Cassandra java-driver-core 4.6.1 #2400

patriknw opened this issue Sep 10, 2020 · 1 comment · Fixed by #2416
Milestone

Comments

@patriknw
Copy link
Member

CVE-2020-11612 in Netty 4.1.45, fixed in 4.1.46

Related issues

There are newer versions of the driver:

  • java-driver-core 4.7.2 still has Netty 4.1.45 dependency
  • java-driver-core 4.8.0 and 4.9.0 has Netty 4.1.51 dependency

If we can't update the driver in patch release in a compatible way we should be able to force the netty dependency to 4.1.46 or latest 4.1.51.

@ennru
Copy link
Member

ennru commented Sep 14, 2020

They seem to do minor releases at a steady pace.

https://docs.datastax.com/en/developer/java-driver/4.9/changelog/

What do we know about the bin-compatibility story in the Cassandra Java driver?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants