Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update the Netty to latest version (4.1.108.Final) - Vulnerability CVE-2024-29025 #964

Open
bebaskar opened this issue Jun 19, 2024 · 1 comment

Comments

@bebaskar
Copy link

Currently Finagle library has Netty version as 4.1.100.Final which is vulnerable with https://gist.github.com/vietj/f558b8ea81ec6505f1e9a6ca283c9ae3 ( CVE-2024-29025) .

To remove this Netty version should be >= 4.1.108 Final.

Steps to reproduce the behavior:

Scan the docker image with twistcli (https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/tools/twistcli_scan_images)

@bebaskar
Copy link
Author

Please can some help to update the netty that fixes the vulnerability

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
1 participant