Details
-
Task
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
3.5.9
-
None
Description
The aim of this ticket to fix all CVEs on branch-3.5 before the last 3.5.10 release.
branch-3.5 is quite outdated when it comes to CVE fixes. I already backported
ZOOKEEPER-4455 (remove log4j and add reload4j) but other dependencies are also outdated. Most probably the dependency plugin also needs to be updated to avoid the netty-transport related false-positive CVEs.
Attachments
Issue Links
- links to