[ https://issues.apache.org/jira/browse/ZOOKEEPER-4272?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Dominique Mongelli updated ZOOKEEPER-4272: ------------------------------------------ Affects Version/s: (was: 3.5.8) (was: 3.6.1) Description: Our security tool raised the following security flaw on zookeeper 3.6.2: [https://nvd.nist.gov/vuln/detail/CVE-2021-21295] It is a vulnerability related to jar *netty-codec-4.1.50.Final.jar*. Based on netty issue tracker, the vulnerability is fixed in 4.1.60.Final: [https://github.com/netty/netty/security/advisories/GHSA-wm47-8v5p-wjpj] was: Our security tool raised the following security flaw on kafka 2.7: [https://nvd.nist.gov/vuln/detail/CVE-2021-21295] It is a vulnerability related to jar *netty-codec-4.1.51.Final.jar*. Looking at source code, the netty-codec in trunk and 2.7.0 branches are still vulnerable. Based on netty issue tracker, the vulnerability is fixed in 4.1.60.Final: [https://github.com/netty/netty/security/advisories/GHSA-wm47-8v5p-wjpj] Issue Type: Bug (was: Task) > Upgrade Netty library to > 4.1.60 due to security vulnerability CVE-2021-21295 > ------------------------------------------------------------------------------ > > Key: ZOOKEEPER-4272 > URL: https://issues.apache.org/jira/browse/ZOOKEEPER-4272 > Project: ZooKeeper > Issue Type: Bug > Components: security > Affects Versions: 3.6.2 > Reporter: Dominique Mongelli > Priority: Major > > Our security tool raised the following security flaw on zookeeper 3.6.2: > [https://nvd.nist.gov/vuln/detail/CVE-2021-21295] > It is a vulnerability related to jar *netty-codec-4.1.50.Final.jar*. > Based on netty issue tracker, the vulnerability is fixed in 4.1.60.Final: > [https://github.com/netty/netty/security/advisories/GHSA-wm47-8v5p-wjpj] -- This message was sent by Atlassian Jira (v8.3.4#803005)