Done
Details
Assignee
Julian LadischJulian LadischReporter
Julian LadischJulian LadischLabels
Priority
P2Development Team
ThunderjetFix versions
Release
Ramsons (R2 2024)RCA Group
Third party component integrationAffected releases
Quesnelia (R1 2024)Poppy (R2 2023)TestRail: Cases
Open TestRail: CasesTestRail: Runs
Open TestRail: Runs
Details
Details
Assignee
Julian Ladisch
Julian LadischReporter
Julian Ladisch
Julian LadischLabels
Priority
Development Team
Thunderjet
Fix versions
Release
Ramsons (R2 2024)
RCA Group
Third party component integration
Affected releases
Quesnelia (R1 2024)
Poppy (R2 2023)
TestRail: Cases
Open TestRail: Cases
TestRail: Runs
Open TestRail: Runs
Created September 3, 2024 at 4:14 PM
Updated October 14, 2024 at 12:44 PM
Resolved September 5, 2024 at 5:54 AM
Upgrade Vert.x from 4.5.4 to 4.5.9.
This indirectly upgrades Netty from 4.1.107.Final to 4.1.111.Final fixing Allocation of Resources Without Limits or Throttling: https://security.snyk.io/package/maven/io.netty:netty-codec-http/4.1.107.Final
Upgrade Apache SSHD/SFTP from 2.8.0/2.9.0 to 2.13.2 fixing vulnerabilities:
https://security.snyk.io/package/maven/org.apache.sshd:sshd-common/2.9.0
https://security.snyk.io/package/maven/org.apache.sshd:sshd-core/2.9.0
https://security.snyk.io/package/maven/org.apache.sshd:sshd-sftp/2.9.0
To avoid diverging versions use dependencyManagement for vertx and testcontainers.