Skip to content

Further vulnerabilities reported against dsbulk 1.11.0 #504

@alberto-bortolan

Description

@alberto-bortolan

The following vulnerabilities have been reported in addition to those already listed in #497 and #499 :

MEDIUM CVE-2024-29025 io.netty:netty-codec-http /apps/dsbulk-1.11.0/lib/netty-codec-http-4.1.94.Final.jar
Fixed in netty 4.1.108

MEDIUM CVE-2024-12798 ch.qos.logback:logback-core dsbulk-1.11.0/lib/logback-core-1.2.11.jar
LOW CVE-2024-12801 ch.qos.logback:logback-core dsbulk-1.11.0/lib/logback-core-1.2.11.jar
Both fixed in logback 1.3.15

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions