Skip to content

Please upgrade dependencies because of netty vulnerability #1229

@basdebakker

Description

@basdebakker

Describe the bug

The versions of the dependencies rds and sts that are currently included depend on io.netty:netty-buffer:4.1.114.Final, which has a vulnerability, see https://www.cve.org/CVERecord?id=CVE-2024-47535. The latest version of those packages depend on the fixed version of netty.

Expected Behavior

Include latest version of netty.

What plugins are used? What other connection properties were set?

N/A

Current Behavior

io.netty:netty-buffer:4.1.114.Final is included.

Reproduction Steps

Include dependency on aws-advanced-jdbc-wrapper 2.5.3 in project.

Possible Solution

Upgrade the versions of the dependencies.

Additional Information/Context

No response

The AWS Advanced JDBC Driver version used

2.5.3

JDK version used

openjdk version "21.0.2" 2024-01-16 LTS OpenJDK Runtime Environment Temurin-21.0.2+13 (build 21.0.2+13-LTS) OpenJDK 64-Bit Server VM Temurin-21.0.2+13 (build 21.0.2+13-LTS, mixed mode, sharing)

Operating System and version

Windows 11 Enterprise 22H2

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions