Skip to content

Commit f1ed7fe

Browse files
committed
[NOID] Update lettuce-core to 6.5.4.RELEASE to mitigate CVE-2024-47535, CVE-2025-24970 and CVE-2025-25193
1 parent 0403d53 commit f1ed7fe

File tree

5 files changed

+28
-28
lines changed

5 files changed

+28
-28
lines changed

LICENSES.txt

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -164,11 +164,11 @@ Apache-2.0
164164
mercator_2.12-0.2.1.jar
165165
metrics-core-3.2.4.jar
166166
netty-all-4.1.100.Final.jar
167-
netty-buffer-4.1.119.Final.jar
168-
netty-codec-4.1.119.Final.jar
167+
netty-buffer-4.1.126.Final.jar
168+
netty-codec-4.1.126.Final.jar
169169
netty-codec-dns-4.1.100.Final.jar
170170
netty-codec-haproxy-4.1.100.Final.jar
171-
netty-codec-http-4.1.119.Final.jar
171+
netty-codec-http-4.1.126.Final.jar
172172
netty-codec-http2-4.1.100.Final.jar
173173
netty-codec-memcache-4.1.100.Final.jar
174174
netty-codec-mqtt-4.1.100.Final.jar
@@ -177,24 +177,24 @@ Apache-2.0
177177
netty-codec-socks-4.1.100.Final.jar
178178
netty-codec-stomp-4.1.100.Final.jar
179179
netty-codec-xml-4.1.100.Final.jar
180-
netty-common-4.1.119.Final.jar
181-
netty-handler-4.1.119.Final.jar
180+
netty-common-4.1.126.Final.jar
181+
netty-handler-4.1.126.Final.jar
182182
netty-handler-proxy-4.1.100.Final.jar
183183
netty-handler-ssl-ocsp-4.1.100.Final.jar
184-
netty-resolver-4.1.119.Final.jar
184+
netty-resolver-4.1.126.Final.jar
185185
netty-resolver-dns-4.1.100.Final.jar
186186
netty-resolver-dns-classes-macos-4.1.100.Final.jar
187187
netty-resolver-dns-native-macos-4.1.100.Final-osx-aarch_64.jar
188188
netty-resolver-dns-native-macos-4.1.100.Final-osx-x86_64.jar
189-
netty-transport-4.1.119.Final.jar
190-
netty-transport-classes-epoll-4.1.119.Final.jar
189+
netty-transport-4.1.126.Final.jar
190+
netty-transport-classes-epoll-4.1.126.Final.jar
191191
netty-transport-classes-kqueue-4.1.100.Final.jar
192-
netty-transport-native-epoll-4.1.119.Final-linux-aarch_64.jar
193-
netty-transport-native-epoll-4.1.119.Final-linux-x86_64.jar
194-
netty-transport-native-epoll-4.1.119.Final.jar
192+
netty-transport-native-epoll-4.1.126.Final-linux-aarch_64.jar
193+
netty-transport-native-epoll-4.1.126.Final-linux-x86_64.jar
194+
netty-transport-native-epoll-4.1.126.Final.jar
195195
netty-transport-native-kqueue-4.1.100.Final-osx-aarch_64.jar
196196
netty-transport-native-kqueue-4.1.100.Final-osx-x86_64.jar
197-
netty-transport-native-unix-common-4.1.119.Final.jar
197+
netty-transport-native-unix-common-4.1.126.Final.jar
198198
netty-transport-rxtx-4.1.100.Final.jar
199199
netty-transport-sctp-4.1.100.Final.jar
200200
netty-transport-udt-4.1.100.Final.jar

NOTICE.txt

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -194,11 +194,11 @@ Apache-2.0
194194
mercator_2.12-0.2.1.jar
195195
metrics-core-3.2.4.jar
196196
netty-all-4.1.100.Final.jar
197-
netty-buffer-4.1.119.Final.jar
198-
netty-codec-4.1.119.Final.jar
197+
netty-buffer-4.1.126.Final.jar
198+
netty-codec-4.1.126.Final.jar
199199
netty-codec-dns-4.1.100.Final.jar
200200
netty-codec-haproxy-4.1.100.Final.jar
201-
netty-codec-http-4.1.119.Final.jar
201+
netty-codec-http-4.1.126.Final.jar
202202
netty-codec-http2-4.1.100.Final.jar
203203
netty-codec-memcache-4.1.100.Final.jar
204204
netty-codec-mqtt-4.1.100.Final.jar
@@ -207,24 +207,24 @@ Apache-2.0
207207
netty-codec-socks-4.1.100.Final.jar
208208
netty-codec-stomp-4.1.100.Final.jar
209209
netty-codec-xml-4.1.100.Final.jar
210-
netty-common-4.1.119.Final.jar
211-
netty-handler-4.1.119.Final.jar
210+
netty-common-4.1.126.Final.jar
211+
netty-handler-4.1.126.Final.jar
212212
netty-handler-proxy-4.1.100.Final.jar
213213
netty-handler-ssl-ocsp-4.1.100.Final.jar
214-
netty-resolver-4.1.119.Final.jar
214+
netty-resolver-4.1.126.Final.jar
215215
netty-resolver-dns-4.1.100.Final.jar
216216
netty-resolver-dns-classes-macos-4.1.100.Final.jar
217217
netty-resolver-dns-native-macos-4.1.100.Final-osx-aarch_64.jar
218218
netty-resolver-dns-native-macos-4.1.100.Final-osx-x86_64.jar
219-
netty-transport-4.1.119.Final.jar
220-
netty-transport-classes-epoll-4.1.119.Final.jar
219+
netty-transport-4.1.126.Final.jar
220+
netty-transport-classes-epoll-4.1.126.Final.jar
221221
netty-transport-classes-kqueue-4.1.100.Final.jar
222-
netty-transport-native-epoll-4.1.119.Final-linux-aarch_64.jar
223-
netty-transport-native-epoll-4.1.119.Final-linux-x86_64.jar
224-
netty-transport-native-epoll-4.1.119.Final.jar
222+
netty-transport-native-epoll-4.1.126.Final-linux-aarch_64.jar
223+
netty-transport-native-epoll-4.1.126.Final-linux-x86_64.jar
224+
netty-transport-native-epoll-4.1.126.Final.jar
225225
netty-transport-native-kqueue-4.1.100.Final-osx-aarch_64.jar
226226
netty-transport-native-kqueue-4.1.100.Final-osx-x86_64.jar
227-
netty-transport-native-unix-common-4.1.119.Final.jar
227+
netty-transport-native-unix-common-4.1.126.Final.jar
228228
netty-transport-rxtx-4.1.100.Final.jar
229229
netty-transport-sctp-4.1.100.Final.jar
230230
netty-transport-udt-4.1.100.Final.jar

docs/asciidoc/modules/ROOT/pages/database-integration/redis.adoc

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ Here is a list of all available Redis procedures:
4545
== Install Dependencies
4646

4747
The Redis procedures have dependencies on a client library that is not included in the APOC Library.
48-
You can download it from https://github.com/lettuce-io/lettuce-core/releases/tag/6.2.5.RELEASE[the lettuce-core repository](except for `netty` jars because they are already included within neo4j)
48+
You can download it from https://github.com/lettuce-io/lettuce-core/releases/tag/6.5.4.RELEASE[the lettuce-core repository](except for `netty` jars because they are already included within neo4j)
4949
or https://github.com/neo4j-contrib/neo4j-apoc-procedures/releases/download/{apoc-release}/apoc-redis-dependencies-{apoc-release}.jar[apoc repository]
5050
Once that file is downloaded, it should be placed in the `plugins` directory and the Neo4j Server restarted.
5151

extra-dependencies/redis/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jar {
1919
}
2020

2121
dependencies {
22-
implementation group: 'io.lettuce', name: 'lettuce-core', version: '6.2.5.RELEASE', {
22+
implementation group: 'io.lettuce', name: 'lettuce-core', version: '6.5.4.RELEASE', {
2323
exclude group: 'io.netty'
2424
}
2525
}

full/build.gradle

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -134,8 +134,8 @@ dependencies {
134134
compileOnly group: 'com.couchbase.client', name: 'java-client', version: '3.3.0', withoutJacksons
135135
testImplementation group: 'com.couchbase.client', name: 'java-client', version: '3.3.0', withoutJacksons
136136

137-
compileOnly group: 'io.lettuce', name: 'lettuce-core', version: '6.2.5.RELEASE'
138-
testImplementation group: 'io.lettuce', name: 'lettuce-core', version: '6.2.5.RELEASE'
137+
compileOnly group: 'io.lettuce', name: 'lettuce-core', version: '6.5.4.RELEASE'
138+
testImplementation group: 'io.lettuce', name: 'lettuce-core', version: '6.5.4.RELEASE'
139139

140140
compileOnly group: 'org.neo4j', name: 'neo4j', version: neo4jVersionEffective
141141

0 commit comments

Comments
 (0)