Skip to content

BEE-2296 Override netty version until AWS releases update#395

Merged
Vlatombe merged 1 commit into
jenkinsci:masterfrom
richbg:master
Mar 17, 2021
Merged

BEE-2296 Override netty version until AWS releases update#395
Vlatombe merged 1 commit into
jenkinsci:masterfrom
richbg:master

Conversation

@richbg
Copy link
Copy Markdown
Contributor

@richbg richbg commented Mar 16, 2021

Overrides netty version bundled with aws-java-sdk as the version 4.1.59.Final is vulnerable
ref
GHSA-wm47-8v5p-wjpj
https://nvd.nist.gov/vuln/detail/CVE-2021-21295

Once this is resolved the override should be removed.
aws/aws-sdk-java#2531

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants