Uploaded image for project: 'Flume'
  1. Flume
  2. FLUME-3385

flume-ng-sdk uses Avro-IPC version with vulnerable version of Jetty

    XMLWordPrintableJSON

Details

    • Dependency upgrade
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 1.9.0
    • 1.10.0
    • None
    • None

    Description

      Vulnerability: https://nvd.nist.gov/vuln/detail/CVE-2011-4461

      Need to upgrade to Avro IPC version 1.9.0 or later which does not depend on the vulnerable version of Jetty (it actually doesn't use Jetty at all)

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              dev-warner Lily Warner
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: