Vulnerability on netty-3.10.6.Final.jar
- Dominant language
- Java
- Stars
- 14.1k
- Forks
- 3.8k
- Avg merge
- 2d 58m
- Merged PRs (30d)
- 233
Description
Druid use both 4.1.48 and 3.10.6.Final vesrions of netty jar of which lower vesrion is security vulnerable
### Affected Version
18.1
### Description
Though most of the netty jars are upgraded to higher version(4.1.48) in druid latest vesrion, itstill use one jar in older vesrion(netty-3.10.6.Final.jar). And this version 3.10.6.Final has security vulnerabilities associated with it.
Anyone working on replacing netty-3.10.6.final as well to latest version?
Contributor guide
Research direction
No file or test is named. Start by locating the dependency declarations that bring in netty-3.10.6.Final.jar alongside Netty 4.1.48, then verify the affected 18.1 dependency tree. Done means the older vulnerable Netty jar is no longer included without breaking Druid's Netty usage.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100