[
https://issues.apache.org/jira/browse/FLUME-3386?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17472474#comment-17472474
]
ASF subversion and git services commented on FLUME-3386:
--------------------------------------------------------
Commit c9d03dbc6cb49f82054b51a1bca5c40973a7eac1 in flume's branch
refs/heads/trunk from Ralph Goers
[ https://gitbox.apache.org/repos/asf?p=flume.git;h=c9d03db ]
FLUME-3386 - upgrade version of netty-all to 4.1.72
> flume-ng-sdk uses vulnerable version of netty
> ---------------------------------------------
>
> Key: FLUME-3386
> URL: https://issues.apache.org/jira/browse/FLUME-3386
> Project: Flume
> Issue Type: Dependency upgrade
> Affects Versions: 1.9.0
> Reporter: Lily Warner
> Priority: Major
>
> Vulnerabilities:
> * [https://nvd.nist.gov/vuln/detail/CVE-2019-16869]
> * [https://nvd.nist.gov/vuln/detail/CVE-2019-20444]
> * [https://nvd.nist.gov/vuln/detail/CVE-2019-20445]
> * sonatype-2020-0103
> * sonatype-2020-0029
> Version to migrate to: 4.1.59 or above
--
This message was sent by Atlassian Jira
(v8.20.1#820001)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]