Details
-
Improvement
-
Status: Resolved
-
Normal
-
Resolution: Fixed
Description
Cassandra 3.11.1 is patched with logback 1.1.3, which contains the security vulnerability described here. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5929
Also update to logback allows a simple date and size rotation policy to
replace the default fixed policy, which is broken by design.
Attachments
Attachments
Issue Links
- is duplicated by
-
CASSANDRA-16464 Upgrade to logback package 1.2.0 or later fix high vulnerabilities
- Resolved
- links to