Browse Source

ZOOKEEPER-4414: Update Netty to 4.1.70.Final

This PR updates Netty to 4.1.70 Final on master. This addresses the following CVEs:
* CVE-2021-37136
* Netty codec/src/main/java/io/netty/handler/codec/compression/Lz4FrameEncoder.java Lz4FrameEncoder::finishEncode() Function Buffer Overflow
* CVE-2021-37137

Author: Frederiko Costa <frederiko.costa@workday.com>

Reviewers: maoling <maoling@apache.org>

Closes #1775 from frederiko/netty-4.1.70.Final
Frederiko Costa 3 years ago
parent
commit
01f935cdeb

+ 1 - 1
pom.xml

@@ -467,7 +467,7 @@
     <mockito.version>3.6.28</mockito.version>
     <hamcrest.version>2.2</hamcrest.version>
     <commons-cli.version>1.4</commons-cli.version>
-    <netty.version>4.1.63.Final</netty.version>
+    <netty.version>4.1.70.Final</netty.version>
     <jetty.version>9.4.43.v20210629</jetty.version>
     <jackson.version>2.10.5.1</jackson.version>
     <jline.version>2.14.6</jline.version>

+ 0 - 0
zookeeper-server/src/main/resources/lib/netty-buffer-4.1.63.Final.LICENSE.txt → zookeeper-server/src/main/resources/lib/netty-buffer-4.1.70.Final.LICENSE.txt


+ 0 - 0
zookeeper-server/src/main/resources/lib/netty-codec-4.1.63.Final.LICENSE.txt → zookeeper-server/src/main/resources/lib/netty-codec-4.1.70.Final.LICENSE.txt


+ 0 - 0
zookeeper-server/src/main/resources/lib/netty-common-4.1.63.Final.LICENSE.txt → zookeeper-server/src/main/resources/lib/netty-common-4.1.70.Final.LICENSE.txt


+ 0 - 0
zookeeper-server/src/main/resources/lib/netty-handler-4.1.63.Final.LICENSE.txt → zookeeper-server/src/main/resources/lib/netty-handler-4.1.70.Final.LICENSE.txt


+ 0 - 0
zookeeper-server/src/main/resources/lib/netty-resolver-4.1.63.Final.LICENSE.txt → zookeeper-server/src/main/resources/lib/netty-resolver-4.1.70.Final.LICENSE.txt


+ 0 - 0
zookeeper-server/src/main/resources/lib/netty-transport-4.1.63.Final.LICENSE.txt → zookeeper-server/src/main/resources/lib/netty-transport-4.1.70.Final.LICENSE.txt


+ 0 - 0
zookeeper-server/src/main/resources/lib/netty-transport-native-epoll-4.1.63.Final.LICENSE.txt → zookeeper-server/src/main/resources/lib/netty-transport-native-epoll-4.1.70.Final.LICENSE.txt


+ 0 - 0
zookeeper-server/src/main/resources/lib/netty-transport-native-unix-common-4.1.63.Final.LICENSE.txt → zookeeper-server/src/main/resources/lib/netty-transport-native-unix-common-4.1.70.Final.LICENSE.txt