Skip to content

Conversation

@merlimat
Copy link
Contributor

@merlimat merlimat commented Jun 8, 2022

Motivation

https://nvd.nist.gov/vuln/detail/CVE-2019-20444#range-6908693

Upgrade from 2.0.4 to 2.0.6

  • doc-not-needed

@merlimat merlimat added this to the 2.11.0 milestone Jun 8, 2022
@merlimat merlimat self-assigned this Jun 8, 2022
@merlimat merlimat marked this pull request as ready for review June 8, 2022 23:28
@github-actions

This comment was marked as outdated.

2 similar comments
@github-actions

This comment was marked as duplicate.

@github-actions

This comment was marked as duplicate.

@merlimat merlimat added doc-not-needed Your PR changes do not impact docs and removed doc-label-missing labels Jun 8, 2022
@merlimat merlimat force-pushed the netty-reactive-streams branch from 4e14e4d to 27668ba Compare June 8, 2022 23:39
@apache apache deleted a comment from github-actions bot Jun 8, 2022
@hezhangjian hezhangjian merged commit 3d7634a into apache:master Jun 9, 2022
mattisonchao pushed a commit that referenced this pull request Jun 11, 2022
@mattisonchao mattisonchao added the cherry-picked/branch-2.9 Archived: 2.9 is end of life label Jun 11, 2022
nicoloboschi pushed a commit to datastax/pulsar that referenced this pull request Jun 13, 2022
zymap added a commit to zymap/pulsar that referenced this pull request Jul 1, 2022
---

*Motivation*

We upgrade the Netty Reactive Stream in the PR apache#15990,
but the asynchttpclient still uses it. We should use
our project dependency to address the CVE.
zymap added a commit that referenced this pull request Jul 5, 2022
* Exclude the Netty Reactive Stream from asynchttpclient
---

*Motivation*

We upgrade the Netty Reactive Stream in the PR #15990,
but the asynchttpclient still uses it. We should use
our project dependency to address the CVE.

* Add the related dependency to the sub module
codelipenghui pushed a commit that referenced this pull request Jul 10, 2022
* Exclude the Netty Reactive Stream from asynchttpclient
---

*Motivation*

We upgrade the Netty Reactive Stream in the PR #15990,
but the asynchttpclient still uses it. We should use
our project dependency to address the CVE.

* Add the related dependency to the sub module

(cherry picked from commit f9e89ed)
nicoloboschi pushed a commit to datastax/pulsar that referenced this pull request Jul 11, 2022
* Exclude the Netty Reactive Stream from asynchttpclient
---

*Motivation*

We upgrade the Netty Reactive Stream in the PR apache#15990,
but the asynchttpclient still uses it. We should use
our project dependency to address the CVE.

* Add the related dependency to the sub module

(cherry picked from commit f9e89ed)
(cherry picked from commit b5479ee)
wuxuanqicn pushed a commit to wuxuanqicn/pulsar that referenced this pull request Jul 14, 2022
* Exclude the Netty Reactive Stream from asynchttpclient
---

*Motivation*

We upgrade the Netty Reactive Stream in the PR apache#15990,
but the asynchttpclient still uses it. We should use
our project dependency to address the CVE.

* Add the related dependency to the sub module
mattisonchao pushed a commit that referenced this pull request Aug 10, 2022
* Exclude the Netty Reactive Stream from asynchttpclient
---

*Motivation*

We upgrade the Netty Reactive Stream in the PR #15990,
but the asynchttpclient still uses it. We should use
our project dependency to address the CVE.

* Add the related dependency to the sub module

(cherry picked from commit f9e89ed)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants