Uploaded image for project: 'ZooKeeper'
  1. ZooKeeper
  2. ZOOKEEPER-4762

Update netty jars to 4.1.99+ to fix CVE-2023-4586

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Critical
    • Resolution: Fixed
    • 3.8.3
    • 3.8.4
    • None
    • None

    Description

      https://nvd.nist.gov/vuln/detail/CVE-2023-4586
      A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.

      Attachments

        Activity

          People

            Unassigned Unassigned
            dpramod Dhoka Pramod
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: