Skip to content

Upgrade netty 4 to fix CVE-2020-11612#9651

Merged
jon-wei merged 1 commit intoapache:masterfrom
ccaominh:netty4-CVE-2020-11612
Apr 9, 2020
Merged

Upgrade netty 4 to fix CVE-2020-11612#9651
jon-wei merged 1 commit intoapache:masterfrom
ccaominh:netty4-CVE-2020-11612

Conversation

@ccaominh
Copy link
Contributor

@ccaominh ccaominh commented Apr 9, 2020

Description

CVE-2020-11612 affects netty 4 versions 4.1.45 or older. Current latest version is 4.41.48.


This PR has:

  • been self-reviewed.
  • added or updated version, license, or notice information in licenses.yaml

Copy link
Contributor

@suneet-s suneet-s left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jihoonson jihoonson added this to the 0.18.0 milestone Apr 9, 2020
@jon-wei jon-wei merged commit eb45981 into apache:master Apr 9, 2020
ccaominh added a commit to ccaominh/druid that referenced this pull request Apr 9, 2020
ccaominh added a commit to ccaominh/druid that referenced this pull request Apr 10, 2020
@ccaominh ccaominh deleted the netty4-CVE-2020-11612 branch April 10, 2020 00:28
jon-wei pushed a commit that referenced this pull request Apr 10, 2020
ccaominh added a commit to implydata/druid-public that referenced this pull request Apr 10, 2020
JulianJaffePinterest pushed a commit to JulianJaffePinterest/druid that referenced this pull request Jun 12, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants