[
https://issues.apache.org/jira/browse/ZOOKEEPER-4390?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17422871#comment-17422871
]
Brahma Reddy Battula commented on ZOOKEEPER-4390:
-------------------------------------------------
[~ananysin] thanks for reporting,Yes, we need to backport to branch-3.5 and
branch-3.6.
[~volcano] PR is raised, please check the following link for same(same is
linked in the jira).
https://github.com/apache/zookeeper/pull/1768/commits/f33d71b329fe08ad179b731141ffb753fc879073
> Backport ZOOKEEPER-4337 for branch-3.5 and branch-3.6
> -----------------------------------------------------
>
> Key: ZOOKEEPER-4390
> URL: https://issues.apache.org/jira/browse/ZOOKEEPER-4390
> Project: ZooKeeper
> Issue Type: Bug
> Components: security
> Affects Versions: 3.5.9
> Reporter: Ananya Singh
> Priority: Major
>
> Our security tool raised the following security flaws on zookeeper 3.5.9:
> CVE-2021-28163:
> [https://nvd.nist.gov/vuln/detail/CVE-2021-28163|https://nvd.nist.gov/vuln/detail/CVE-2021-21295]
> CVE-2021-28169:
> [https://nvd.nist.gov/vuln/detail/CVE-2021-28169|https://nvd.nist.gov/vuln/detail/CVE-2021-21295]
> CVE-2021-34428:
> [https://nvd.nist.gov/vuln/detail/CVE-2021-34428|https://nvd.nist.gov/vuln/detail/CVE-2021-21295]
>
> It is a vulnerability related to jar jetty-http-9.4.35.v20201120.jar
--
This message was sent by Atlassian Jira
(v8.3.4#803005)