Uploaded image for project: 'Cassandra'
  1. Cassandra
  2. CASSANDRA-15873

Update Netty 4.0.44 -> 4.1.50 (fix security/performance issues)

    XMLWordPrintableJSON

    Details

    • Type: Task
    • Status: Open
    • Priority: Normal
    • Resolution: Unresolved
    • Fix Version/s: 3.11.x
    • Component/s: Dependencies
    • Labels:
      None
    • Complexity:
      Low Hanging Fruit
    • Platform:
      All
    • Impacts:
      None
    • Test and Documentation Plan:
      Hide

      TBD

      Show
      TBD

      Description

      See https://issues.apache.org/jira/browse/CASSANDRA-15868 for the same issue on 4.0 / trunk. Attached is an OWASP dependency report for Netty 4.0.44, which identifies 3 of the same vulnerabilities as above.

       

      Additionally, 4.1.50 contains aarch64 native libraries which can improve performance on ARM processors. 

       

        Attachments

        1. unittest_netty.log
          208 kB
          Matt Davis
        2. dependency-check-report.html
          469 kB
          Matt Davis

          Issue Links

            Activity

              People

              • Assignee:
                Unassigned
                Reporter:
                mattsplat Matt Davis
              • Votes:
                0 Vote for this issue
                Watchers:
                4 Start watching this issue

                Dates

                • Created:
                  Updated: