Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[fix][sec] Upgrade async-http-client to 2.12.4 to address CVE-2024-53990 #23732

Merged
merged 3 commits into from
Dec 16, 2024

Conversation

lhotari
Copy link
Member

@lhotari lhotari commented Dec 16, 2024

Motivation

Upgrade to async-http-client 2.12.4 which contains a fix for CVE-2024-53990. See https://lists.apache.org/thread/fpg465pxytqkxbs57h7p3mckn9dwh3zq for more details.

Modifications

Documentation

  • doc
  • doc-required
  • doc-not-needed
  • doc-complete

@lhotari lhotari added this to the 4.1.0 milestone Dec 16, 2024
@lhotari lhotari self-assigned this Dec 16, 2024
@lhotari lhotari changed the title [fix][sec] Upgrade async-http-client to 2.12.4 [fix][sec] Upgrade async-http-client to 2.12.4 to address CVE-2024-53990 Dec 16, 2024
@github-actions github-actions bot added the doc-not-needed Your PR changes do not impact docs label Dec 16, 2024
@codecov-commenter
Copy link

codecov-commenter commented Dec 16, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 74.40%. Comparing base (bbc6224) to head (3d87803).
Report is 794 commits behind head on master.

Additional details and impacted files

Impacted file tree graph

@@             Coverage Diff              @@
##             master   #23732      +/-   ##
============================================
+ Coverage     73.57%   74.40%   +0.83%     
- Complexity    32624    35097    +2473     
============================================
  Files          1877     1945      +68     
  Lines        139502   147510    +8008     
  Branches      15299    16280     +981     
============================================
+ Hits         102638   109761    +7123     
- Misses        28908    29273     +365     
- Partials       7956     8476     +520     
Flag Coverage Δ
inttests 27.27% <ø> (+2.68%) ⬆️
systests 24.35% <ø> (+0.02%) ⬆️
unittests 73.80% <ø> (+0.95%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

see 675 files with indirect coverage changes

@lhotari lhotari merged commit 9a7269a into apache:master Dec 16, 2024
52 of 53 checks passed
lhotari added a commit that referenced this pull request Dec 16, 2024
lhotari added a commit that referenced this pull request Dec 16, 2024
lhotari added a commit that referenced this pull request Dec 16, 2024
nikhil-ctds pushed a commit to datastax/pulsar that referenced this pull request Dec 19, 2024
srinath-ctds pushed a commit to datastax/pulsar that referenced this pull request Dec 23, 2024
@lhotari
Copy link
Member Author

lhotari commented Jan 17, 2025

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants