Describe the bug
our twistlock/Aquasec container scans have found below CVEs in the current netty version.
Affected CVEs
In order to resolve the above CVEs, netty packages need to be upgraded to 4.2.13.Final version.
Regression Issue
Expected Behavior
netty packages need to be upgraded to 4.2.13.Final version.
Current Behavior
netty packages are in the version 4.1.133.Final - which is vulnerable
Reproduction Steps
Use twistlock/aquasec scanner to detect the CVEs.
Possible Solution
Netty version upgrade to the fixed version 4.2.13.Final
Additional Information/Context
No response
AWS Java SDK version used
2.42.25
JDK version used
2.42.25
Operating System and version
linux UBI 9
Describe the bug
our twistlock/Aquasec container scans have found below CVEs in the current netty version.
Affected CVEs
In order to resolve the above CVEs, netty packages need to be upgraded to
4.2.13.Finalversion.Regression Issue
Expected Behavior
netty packages need to be upgraded to
4.2.13.Finalversion.Current Behavior
netty packages are in the version
4.1.133.Final- which is vulnerableReproduction Steps
Use twistlock/aquasec scanner to detect the CVEs.
Possible Solution
Netty version upgrade to the fixed version
4.2.13.FinalAdditional Information/Context
No response
AWS Java SDK version used
2.42.25
JDK version used
2.42.25
Operating System and version
linux UBI 9