Details
-
Improvement
-
Status: Resolved
-
Normal
-
Resolution: Invalid
-
None
-
All
-
None
Description
Several JAR dependencies are flagged in Cassandra 3.11.10 as having vulnerabilities that have been fixed in newer releases.
The following is the Cassandra 3.11.10 source tree for their JAR dependencies: https://github.com/apache/cassandra/tree/181a4969290f1c756089b2993a638fe403bc1314/lib
A possible fix strategy is to simply update the JARs to their newest version. See the JAR files available for each vulnerable library:
- SeeĀ https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-databind/2.9.10.8
- See https://mvnrepository.com/artifact/io.netty/netty-all/4.1.65.Final
- See https://mvnrepository.com/artifact/org.apache.thrift/libthrift/0.9.3-1
- See https://mvnrepository.com/artifact/com.thinkaurelius.thrift/thrift-server/0.3.9
- See https://mvnrepository.com/artifact/com.google.guava/guava/30.1.1-jre
- See https://mvnrepository.com/artifact/ch.qos.logback/logback-core/1.2.3
- See https://mvnrepository.com/artifact/org.yaml/snakeyaml/1.29
- See https://mvnrepository.com/artifact/commons-codec/commons-codec/1.15
Attachments
Issue Links
- duplicates
-
CASSANDRA-16463 high and critical CVEs io.netty to 4.1.42.Final to fix critical and high vulnerabilities
- Resolved
-
CASSANDRA-16462 Upgrade to Jackson Databind 2.9.10.8 or later fix high vulnerabilities
- Resolved
- is cloned by
-
CASSANDRA-16741 Remediate Cassandra 3.11.10 JAR dependency vulnerability - com.google.guava_guava
- Resolved
-
CASSANDRA-16738 Remediate Cassandra 3.11.10 JAR dependency vulnerability - org.yaml_snakeyaml
- Triage Needed
-
CASSANDRA-16739 Remediate Cassandra 3.11.10 JAR dependency vulnerability - org.apache.thrift_libthrift
- Triage Needed
-
CASSANDRA-16740 Remediate Cassandra 3.11.10 JAR dependency vulnerability - ch.qos.logback_logback-core
- Triage Needed
-
CASSANDRA-16742 Remediate Cassandra 3.11.10 JAR dependency vulnerability - commons-codec_commons-codec
- Triage Needed
-
CASSANDRA-16743 Remediate Cassandra 3.11.10 JAR dependency vulnerability - com.thinkaurelius.thrift_thrift-server
- Triage Needed