Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-17955

Bump netty to the latest 4.1.68

    XMLWordPrintableJSON

Details

    Description

      Netty 4.1.68 fixes the following vulnerabilities.

      • Bzip2Decoder doesn't allow setting size restrictions for decompressed data (#CVE-2021-37136)
      • SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary way (#CVE-2021-37137)

      For more details: https://netty.io/news/2021/09/09/4-1-68-Final.html

      Attachments

        Issue Links

          Activity

            People

              tasanuma Takanobu Asanuma
              tasanuma Takanobu Asanuma
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 1h
                  1h