Skip to content

Conversation

@sumit1997sri
Copy link

As part of our security assessment, we conducted a Black Duck scan to identify vulnerabilities in various dependencies. The scan detected multiple CVE (Common Vulnerabilities and Exposures) in the following libraries, which have now been upgraded to more secure versions:
Identified CVEs and Respective Upgrades:
Cassandra-all (v2.2.12 → v3.11.17)
Fixes: CVE-2023-34453, CVE-2023-34454, CVE-2023-34455, CVE-2019-2684, CVE-2020-13946, CVE-2020-17516, CVE-2021-44521, CVE-2016-3427, CVE-2023-43642
Okio (v3.0.0 → v3.4.0)
Fixes: CVE-2023-3635
Netty-All (v4.1.94 → v4.1.116)
Fixes: CVE-2023-44487
Apache Shiro (already at v1.13.0 in Reaper 3.7.0)
Fixes: CVE-2023-34478, CVE-2023-46749, CVE-2023-46750
Major Code Changes:
pom.xml: Updated dependencies (../cassandra-reaper/src/server/pom.xml).
JmxCassandraManagementProxy.java: Modified (./cassandra-reaper/src/server/src/main/java/io/cassandrareaper/management/jmx/JmxCassandraManagementProxy.java).
Added a dummy cassandra.yaml file: Required to resolve test case failures.

…IO from 3.0.0 to 3.4.0, Upgrade netty-all to 4.1.116
@github-actions
Copy link

No linked issues found. Please add the corresponding issues in the pull request description.
Use GitHub automation to close the issue when a PR is merged

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants