[ https://issues.apache.org/jira/browse/SOLR-14296?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Andras Salamon updated SOLR-14296: ---------------------------------- Attachment: SOLR-14296-01.patch Status: Open (was: Open) > Update netty to 4.1.46 > ---------------------- > > Key: SOLR-14296 > URL: https://issues.apache.org/jira/browse/SOLR-14296 > Project: Solr > Issue Type: Bug > Security Level: Public(Default Security Level. Issues are Public) > Reporter: Andras Salamon > Priority: Minor > Attachments: SOLR-14296-01.patch > > > There are two CVEs against the current netty version: > [https://nvd.nist.gov/vuln/detail/CVE-2019-20444] > [https://nvd.nist.gov/vuln/detail/CVE-2019-20445] > Although solr is not affected it would be still good to update netty. > The first non-affected netty version is 4.1.45 but during the update I've > found a netty bug ( [https://github.com/netty/netty/issues/10017] ) so it's > better to update to 4.1.46 -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org For additional commands, e-mail: issues-h...@lucene.apache.org