Skip to content

Commit f52ac04

Browse files
nicoloboschimerlimat
authored andcommitted
[security] Upgrade Netty to 4.1.72 - CVE-2021-43797 (apache#13328)
* [security] Upgrade Netty to 4.1.72 * fix licenses files
1 parent 2db23b8 commit f52ac04

File tree

4 files changed

+41
-37
lines changed

4 files changed

+41
-37
lines changed

buildtools/pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -105,7 +105,7 @@
105105
<dependency>
106106
<groupId>io.netty</groupId>
107107
<artifactId>netty-common</artifactId>
108-
<version>4.1.68.Final</version>
108+
<version>4.1.72.Final</version>
109109
<scope>test</scope>
110110
</dependency>
111111
</dependencies>

distribution/server/src/assemble/LICENSE.bin.txt

Lines changed: 20 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -352,24 +352,26 @@ The Apache Software License, Version 2.0
352352
- org.apache.commons-commons-compress-1.21.jar
353353
- org.apache.commons-commons-lang3-3.11.jar
354354
* Netty
355-
- io.netty-netty-buffer-4.1.68.Final.jar
356-
- io.netty-netty-codec-4.1.68.Final.jar
357-
- io.netty-netty-codec-dns-4.1.68.Final.jar
358-
- io.netty-netty-codec-http-4.1.68.Final.jar
359-
- io.netty-netty-codec-http2-4.1.68.Final.jar
360-
- io.netty-netty-codec-socks-4.1.68.Final.jar
361-
- io.netty-netty-codec-haproxy-4.1.68.Final.jar
362-
- io.netty-netty-common-4.1.68.Final.jar
363-
- io.netty-netty-handler-4.1.68.Final.jar
364-
- io.netty-netty-handler-proxy-4.1.68.Final.jar
365-
- io.netty-netty-resolver-4.1.68.Final.jar
366-
- io.netty-netty-resolver-dns-4.1.68.Final.jar
367-
- io.netty-netty-transport-4.1.68.Final.jar
368-
- io.netty-netty-transport-native-epoll-4.1.68.Final-linux-x86_64.jar
369-
- io.netty-netty-transport-native-epoll-4.1.68.Final.jar
370-
- io.netty-netty-transport-native-unix-common-4.1.68.Final.jar
371-
- io.netty-netty-transport-native-unix-common-4.1.68.Final-linux-x86_64.jar
372-
- io.netty-netty-tcnative-boringssl-static-2.0.42.Final.jar
355+
- io.netty-netty-buffer-4.1.72.Final.jar
356+
- io.netty-netty-codec-4.1.72.Final.jar
357+
- io.netty-netty-codec-dns-4.1.72.Final.jar
358+
- io.netty-netty-codec-http-4.1.72.Final.jar
359+
- io.netty-netty-codec-http2-4.1.72.Final.jar
360+
- io.netty-netty-codec-socks-4.1.72.Final.jar
361+
- io.netty-netty-codec-haproxy-4.1.72.Final.jar
362+
- io.netty-netty-common-4.1.72.Final.jar
363+
- io.netty-netty-handler-4.1.72.Final.jar
364+
- io.netty-netty-handler-proxy-4.1.72.Final.jar
365+
- io.netty-netty-resolver-4.1.72.Final.jar
366+
- io.netty-netty-resolver-dns-4.1.72.Final.jar
367+
- io.netty-netty-transport-4.1.72.Final.jar
368+
- io.netty-netty-transport-classes-epoll-4.1.72.Final.jar
369+
- io.netty-netty-transport-native-epoll-4.1.72.Final-linux-x86_64.jar
370+
- io.netty-netty-transport-native-epoll-4.1.72.Final.jar
371+
- io.netty-netty-transport-native-unix-common-4.1.72.Final.jar
372+
- io.netty-netty-transport-native-unix-common-4.1.72.Final-linux-x86_64.jar
373+
- io.netty-netty-tcnative-boringssl-static-2.0.46.Final.jar
374+
- io.netty-netty-tcnative-classes-2.0.46.Final.jar
373375
* Prometheus client
374376
- io.prometheus-simpleclient-0.5.0.jar
375377
- io.prometheus-simpleclient_common-0.5.0.jar

pom.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -108,8 +108,8 @@ flexible messaging model and an intuitive client API.</description>
108108
<snappy.version>1.1.7</snappy.version> <!-- ZooKeeper server -->
109109
<dropwizardmetrics.version>3.2.5</dropwizardmetrics.version> <!-- ZooKeeper server -->
110110
<curator.version>5.1.0</curator.version>
111-
<netty.version>4.1.68.Final</netty.version>
112-
<netty-tc-native.version>2.0.42.Final</netty-tc-native.version>
111+
<netty.version>4.1.72.Final</netty.version>
112+
<netty-tc-native.version>2.0.46.Final</netty-tc-native.version>
113113
<jetty.version>9.4.43.v20210629</jetty.version>
114114
<conscrypt.version>2.5.2</conscrypt.version>
115115
<jersey.version>2.34</jersey.version>

pulsar-sql/presto-distribution/LICENSE

Lines changed: 18 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -233,23 +233,25 @@ The Apache Software License, Version 2.0
233233
- commons-lang3-3.11.jar
234234
* Netty
235235
- netty-3.10.6.Final.jar
236-
- netty-buffer-4.1.68.Final.jar
237-
- netty-codec-4.1.68.Final.jar
238-
- netty-codec-dns-4.1.68.Final.jar
239-
- netty-codec-http-4.1.68.Final.jar
240-
- netty-codec-haproxy-4.1.68.Final.jar
241-
- netty-codec-socks-4.1.68.Final.jar
242-
- netty-handler-proxy-4.1.68.Final.jar
243-
- netty-common-4.1.68.Final.jar
244-
- netty-handler-4.1.68.Final.jar
236+
- netty-buffer-4.1.72.Final.jar
237+
- netty-codec-4.1.72.Final.jar
238+
- netty-codec-dns-4.1.72.Final.jar
239+
- netty-codec-http-4.1.72.Final.jar
240+
- netty-codec-haproxy-4.1.72.Final.jar
241+
- netty-codec-socks-4.1.72.Final.jar
242+
- netty-handler-proxy-4.1.72.Final.jar
243+
- netty-common-4.1.72.Final.jar
244+
- netty-handler-4.1.72.Final.jar
245245
- netty-reactive-streams-2.0.4.jar
246-
- netty-resolver-4.1.68.Final.jar
247-
- netty-resolver-dns-4.1.68.Final.jar
248-
- netty-tcnative-boringssl-static-2.0.42.Final.jar
249-
- netty-transport-4.1.68.Final.jar
250-
- netty-transport-native-epoll-4.1.68.Final-linux-x86_64.jar
251-
- netty-transport-native-unix-common-4.1.68.Final.jar
252-
- netty-transport-native-unix-common-4.1.68.Final-linux-x86_64.jar
246+
- netty-resolver-4.1.72.Final.jar
247+
- netty-resolver-dns-4.1.72.Final.jar
248+
- netty-tcnative-boringssl-static-2.0.46.Final.jar
249+
- netty-tcnative-classes-2.0.46.Final.jar
250+
- netty-transport-4.1.72.Final.jar
251+
- netty-transport-classes-epoll-4.1.72.Final.jar
252+
- netty-transport-native-epoll-4.1.72.Final-linux-x86_64.jar
253+
- netty-transport-native-unix-common-4.1.72.Final.jar
254+
- netty-transport-native-unix-common-4.1.72.Final-linux-x86_64.jar
253255
* Joda Time
254256
- joda-time-2.10.5.jar
255257
* Jetty

0 commit comments

Comments
 (0)