Skip to content

High and critical CVEs found on netty packages #6994

@Poojitha-R-Rao

Description

@Poojitha-R-Rao

Describe the bug

our twistlock/Aquasec container scans have found below CVEs in the current netty version.

Affected CVEs

In order to resolve the above CVEs, netty packages need to be upgraded to 4.2.13.Final version.

Regression Issue

  • Select this option if this issue appears to be a regression.

Expected Behavior

netty packages need to be upgraded to 4.2.13.Final version.

Current Behavior

netty packages are in the version 4.1.133.Final - which is vulnerable

Reproduction Steps

Use twistlock/aquasec scanner to detect the CVEs.

Possible Solution

Netty version upgrade to the fixed version 4.2.13.Final

Additional Information/Context

No response

AWS Java SDK version used

2.42.25

JDK version used

2.42.25

Operating System and version

linux UBI 9

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugThis issue is a bug.closing-soonThis issue will close in 4 days unless further comments are made.p2This is a standard priority issue

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions