Skip to content

Conversation

@ctubbsii
Copy link
Member

Bump ZooKeeper to 3.8.3 to address warnings about CVE-2023-44981

(Note: this CVE affects SASL-configured server deployments of ZK, not ZK client code, like how Accumulo uses it, but this removes the warning from GitHub about critical vulnerabilities in Accumulo, and in general, Accumulo tries to develop against the latest patched version of a particular release anyway.)

@ctubbsii ctubbsii self-assigned this Oct 27, 2023
Bump ZooKeeper to 3.8.3 to address warnings about CVE-2023-44981

(Note: this CVE affects SASL-configured server deployments of ZK, not ZK
client code, like how Accumulo uses it, but this removes the warning
from GitHub about critical vulnerabilities in Accumulo, and in general,
Accumulo tries to develop against the latest patched version of a
particular release anyway.)
@ctubbsii ctubbsii changed the title Bump ZooKeeper CVE-2023-44981 Bump ZooKeeper for CVE-2023-44981 Oct 27, 2023
@ctubbsii ctubbsii merged commit f79bf07 into apache:2.1 Oct 30, 2023
@ctubbsii ctubbsii deleted the zk-cve branch October 30, 2023 17:05
@ctubbsii ctubbsii modified the milestones: 3.1.0, 2.1.3 Jul 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants