apache / apache/druid

Vulnerability on netty-3.10.6.Final.jar

Open
#9,979 6 comments 4 reactions 0 assignees View on GitHub
Security
Dominant language
Java
Stars
14.1k
Forks
3.8k
Avg merge
2d 58m
Merged PRs (30d)
233

Description

Druid use both 4.1.48 and 3.10.6.Final vesrions of netty jar of which lower vesrion is security vulnerable

### Affected Version

18.1

### Description

Though most of the netty jars are upgraded to higher version(4.1.48) in druid latest vesrion, itstill use one jar in older vesrion(netty-3.10.6.Final.jar). And this version 3.10.6.Final has security vulnerabilities associated with it.
Anyone working on replacing netty-3.10.6.final as well to latest version?

Contributor guide

Open the contributing guide

Research direction

No file or test is named. Start by locating the dependency declarations that bring in netty-3.10.6.Final.jar alongside Netty 4.1.48, then verify the affected 18.1 dependency tree. Done means the older vulnerable Netty jar is no longer included without breaking Druid's Netty usage.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.