Uploaded image for project: 'Apache Cassandra'
  1. Apache Cassandra
  2. CASSANDRA-15873

Update Netty 4.0.44 -> 4.1.50 (fix security/performance issues)

    XMLWordPrintableJSON

Details

    • Task
    • Status: Resolved
    • Normal
    • Resolution: Fixed
    • 3.11.x
    • Dependencies
    • None
    • Low Hanging Fruit
    • All
    • None
    • Hide

      TBD

      Show
      TBD

    Description

      See https://issues.apache.org/jira/browse/CASSANDRA-15868 for the same issue on 4.0 / trunk. Attached is an OWASP dependency report for Netty 4.0.44, which identifies 3 of the same vulnerabilities as above.

       

      Additionally, 4.1.50 contains aarch64 native libraries which can improve performance on ARM processors. 

       

      Attachments

        1. dependency-check-report.html
          469 kB
          Matt Davis
        2. unittest_netty.log
          208 kB
          Matt Davis

        Issue Links

          Activity

            People

              Unassigned Unassigned
              mattsplat Matt Davis
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: