[fix][sec] Upgrade async-http-client to 2.12.4 to address CVE-2024-53990#23732
Merged
lhotari merged 3 commits intoapache:masterfrom Dec 16, 2024
Merged
[fix][sec] Upgrade async-http-client to 2.12.4 to address CVE-2024-53990#23732lhotari merged 3 commits intoapache:masterfrom
lhotari merged 3 commits intoapache:masterfrom
Conversation
This was referenced Dec 16, 2024
nodece
approved these changes
Dec 16, 2024
dao-jun
approved these changes
Dec 16, 2024
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## master #23732 +/- ##
============================================
+ Coverage 73.57% 74.40% +0.83%
- Complexity 32624 35097 +2473
============================================
Files 1877 1945 +68
Lines 139502 147510 +8008
Branches 15299 16280 +981
============================================
+ Hits 102638 109761 +7123
- Misses 28908 29273 +365
- Partials 7956 8476 +520
Flags with carried forward coverage won't be shown. Click here to find out more. |
3 tasks
nikhil-ctds
pushed a commit
to datastax/pulsar
that referenced
this pull request
Dec 19, 2024
(apache#23732) (cherry picked from commit 9a7269a) (cherry picked from commit 9c04964)
srinath-ctds
pushed a commit
to datastax/pulsar
that referenced
this pull request
Dec 23, 2024
(apache#23732) (cherry picked from commit 9a7269a) (cherry picked from commit 9c04964)
Member
Author
|
The releases are in-progress to include this fix. Ongoing vote threads: |
hanmz
pushed a commit
to hanmz/pulsar
that referenced
this pull request
Feb 12, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Upgrade to async-http-client 2.12.4 which contains a fix for CVE-2024-53990. See https://lists.apache.org/thread/fpg465pxytqkxbs57h7p3mckn9dwh3zq for more details.
Modifications
com.sun.activation:javax.activationwithcom.sun.activation:jakarta.activationDocumentation
docdoc-requireddoc-not-neededdoc-complete