Done
Details
Assignee
Viachaslau KhandramaiViachaslau Khandramai(Deactivated)Reporter
Julian LadischJulian LadischPriority
P2Story Points
1Development Team
FirebirdFix versions
RCA Group
Related dependency upgradeTestRail: Cases
Open TestRail: CasesTestRail: Runs
Open TestRail: Runs
Details
Details
Assignee
Viachaslau Khandramai
Viachaslau Khandramai(Deactivated)Reporter
Julian Ladisch
Julian LadischPriority
Story Points
1
Development Team
Firebird
Fix versions
RCA Group
Related dependency upgrade
TestRail: Cases
Open TestRail: Cases
TestRail: Runs
Open TestRail: Runs
Created December 22, 2022 at 6:39 PM
Updated February 22, 2023 at 1:21 PM
Resolved February 8, 2023 at 3:16 PM
Upgrade aws-sdk-java from 2.17.267 to 2.19.1. This indirectly upgrades Netty from 4.1.77.Final to 4.1.86.Final fixing HTTP Response Splitting: https://nvd.nist.gov/vuln/detail/CVE-2022-41915
Upgrade minio from 8.4.5 to 8.4.6. This indirectly upgrades jackson-databind from 2.13.2.2 to 2.13.4.2 fixing Denial of Service (DoS): https://nvd.nist.gov/vuln/detail/CVE-2022-42003 , https://nvd.nist.gov/vuln/detail/CVE-2022-42004