-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Netty requires update to 5.0.0 to resolve vulnerability #2251
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
According to a few comments in Netty's issue tracker,
And it was withdrawn: Which tool reported that to you, @BrHowell? I assume it needs to be configured to ignore that CVE. |
But merging #2245 would be good, though. |
Yes I ended up discovering that withdrawal, and so we're now ignoring the CVE as we're covered by 4.1.100.Final and up. I forgot about coming back to this issue to update, sorry. I'll close it. |
@BrHowell please note that 4.1.100.Final does not "cover" the CVE. The relevant netty API has remained unchanged. It is simply a false positive CVE. |
CVE-2023-4586 has been published, affecting versions of netty prior to 5.0.0
The text was updated successfully, but these errors were encountered: