New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade Infinispan in all active Jetty branches #6687
Comments
Also, about our Hibernate version, all version of Hibernate up to version Our hibernate usage is tied to our infinispan usage, so upgrading infinispan to version might not be sufficient. Eg: Infinispan |
I think this might potentially be difficult: there's a chance that infinispan has changed to use their own threads for reads and maybe not allow a classloader to be set on them ... see my last comment on #6057 |
Signed-off-by: Jan Bartel <janb@webtide.com>
Signed-off-by: Jan Bartel <janb@webtide.com>
Signed-off-by: Jan Bartel <janb@webtide.com>
Signed-off-by: Jan Bartel <janb@webtide.com>
* Issue #6687 Update to infinispan 11.0.11 Signed-off-by: Jan Bartel <janb@webtide.com> * fix upperbound dependency * use infinispan bom Signed-off-by: Olivier Lamy <oliver.lamy@gmail.com> Co-authored-by: Olivier Lamy <oliver.lamy@gmail.com>
Updated to infinispan version 11.0.11 for jetty-10 and jetty-11 via PR #6766 |
* Issue #6687 Update to infinispan 11.0.11 Signed-off-by: Jan Bartel <janb@webtide.com> * fix upperbound dependency * use infinispan bom Signed-off-by: Olivier Lamy <oliver.lamy@gmail.com> Co-authored-by: Olivier Lamy <oliver.lamy@gmail.com>
Done. |
Jetty version(s)
9.4.x, 10.0.x, and 11.0.x
Description
Our usage of infinispan is getting long in the tooth.
We have Infinispan
9.4.8.Final
in all of our branches.Which uses Hibernate
5.10.3.Final
Infinispan version 9.4.8.Final is subject to CVE-2019-10158, and CVE-2019-10174.
Infinispan version 12.1.7.Final has been released
We need to upgrade, and should at least skip Infinispan 10.x and start investigating using version 11.x or newer. (There are a few CVEs in the infinispan 10.x series we want to avoid as well)
It should be noted that the Docker Hub for infinispan has also moved.
We are using
jboss/infinispan-server
, but the new location isinfinispan/server
The text was updated successfully, but these errors were encountered: