[jira] [Commented] (CASSANDRA-18808) netty-handler vulnerability: CVE-2023-4586

2023-12-11 Thread Michael Semb Wever (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18808?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17795487#comment-17795487 ] Michael Semb Wever commented on CASSANDRA-18808: [~smiklosovic], do you want to

[jira] [Commented] (CASSANDRA-18808) netty-handler vulnerability: CVE-2023-4586

2023-12-11 Thread Brandon Williams (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18808?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17795405#comment-17795405 ] Brandon Williams commented on CASSANDRA-18808: -- This is no longer failing OWASP, and

[jira] [Commented] (CASSANDRA-18808) netty-handler vulnerability: CVE-2023-4586

2023-10-11 Thread Brandon Williams (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18808?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17774007#comment-17774007 ] Brandon Williams commented on CASSANDRA-18808: -- I'm not sure what to think about this

[jira] [Commented] (CASSANDRA-18808) netty-handler vulnerability: CVE-2023-4586

2023-10-10 Thread Michael Semb Wever (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18808?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17773771#comment-17773771 ] Michael Semb Wever commented on CASSANDRA-18808: any updates [~norman] ? >

[jira] [Commented] (CASSANDRA-18808) netty-handler vulnerability: CVE-2023-4586

2023-09-28 Thread Norman Maurer (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18808?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17770135#comment-17770135 ] Norman Maurer commented on CASSANDRA-18808: --- Sorry I didn't have time yet but its on my

[jira] [Commented] (CASSANDRA-18808) netty-handler vulnerability: CVE-2023-4586

2023-09-19 Thread Norman Maurer (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18808?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17766866#comment-17766866 ] Norman Maurer commented on CASSANDRA-18808: --- Ok will do tomorrow latest. > netty-handler

[jira] [Commented] (CASSANDRA-18808) netty-handler vulnerability: CVE-2023-4586

2023-09-19 Thread Brandon Williams (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18808?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17766865#comment-17766865 ] Brandon Williams commented on CASSANDRA-18808: -- I don't think it's currently enabled,

[jira] [Commented] (CASSANDRA-18808) netty-handler vulnerability: CVE-2023-4586

2023-09-19 Thread Norman Maurer (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18808?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17766864#comment-17766864 ] Norman Maurer commented on CASSANDRA-18808: --- I can also verify and do a PR if needed...

[jira] [Commented] (CASSANDRA-18808) netty-handler vulnerability: CVE-2023-4586

2023-09-19 Thread Brandon Williams (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18808?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17766853#comment-17766853 ] Brandon Williams commented on CASSANDRA-18808: -- [~jmeredithco] git blame says you are

[jira] [Commented] (CASSANDRA-18808) netty-handler vulnerability: CVE-2023-4586

2023-09-19 Thread Norman Maurer (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18808?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17766849#comment-17766849 ] Norman Maurer commented on CASSANDRA-18808: --- Netty does not enable hostname verification

[jira] [Commented] (CASSANDRA-18808) netty-handler vulnerability: CVE-2023-4586

2023-09-19 Thread Brandon Williams (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18808?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17766847#comment-17766847 ] Brandon Williams commented on CASSANDRA-18808: -- Still no updates here. [~norman] do

[jira] [Commented] (CASSANDRA-18808) netty-handler vulnerability: CVE-2023-4586

2023-08-31 Thread Brandon Williams (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18808?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17760849#comment-17760849 ] Brandon Williams commented on CASSANDRA-18808: -- A CVE has been created but there is no

[jira] [Commented] (CASSANDRA-18808) netty-handler vulnerability: CVE-2023-4586

2023-08-30 Thread Brandon Williams (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18808?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17760407#comment-17760407 ] Brandon Williams commented on CASSANDRA-18808: -- I'm not able to find anything on this