Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

BEE-2296 Override netty version until AWS releases update #395

Merged
merged 1 commit into from
Mar 17, 2021

Conversation

richbg
Copy link
Contributor

@richbg richbg commented Mar 16, 2021

Overrides netty version bundled with aws-java-sdk as the version 4.1.59.Final is vulnerable
ref
GHSA-wm47-8v5p-wjpj
https://nvd.nist.gov/vuln/detail/CVE-2021-21295

Once this is resolved the override should be removed.
aws/aws-sdk-java#2531

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants