Is there a plan to release 4.8.4 with newer Netty (w/o CVEs)? #2221
pskowronek
started this conversation in
General
Replies: 2 comments 2 replies
-
|
upgrade to 4.9.x |
Beta Was this translation helpful? Give feedback.
1 reply
-
|
micronaut-platform v4.9.3 still has some CVEs from Netty : |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
It seems that micronaut-platform v4.8.3 depends on vulnerable version of netty (4.1.119.Final).
CVEs:
micronaut-platform v4.8.3 has dependency on micronaut-http-netty v4.8.18 - see vulnerability report over there.
Those CVEs were addressed in Netty (netty-codec, netty-codec-http2) and micronaut-http-netty v4.8.19 now depends on the newer versions of netty.
Beta Was this translation helpful? Give feedback.
All reactions