-
Notifications
You must be signed in to change notification settings - Fork 3.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[fix][sec] Upgrade async-http-client to 2.12.4 to address CVE-2024-53990 #23732
Conversation
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## master #23732 +/- ##
============================================
+ Coverage 73.57% 74.40% +0.83%
- Complexity 32624 35097 +2473
============================================
Files 1877 1945 +68
Lines 139502 147510 +8008
Branches 15299 16280 +981
============================================
+ Hits 102638 109761 +7123
- Misses 28908 29273 +365
- Partials 7956 8476 +520
Flags with carried forward coverage won't be shown. Click here to find out more. |
(apache#23732) (cherry picked from commit 9a7269a) (cherry picked from commit 9c04964)
(apache#23732) (cherry picked from commit 9a7269a) (cherry picked from commit 9c04964)
The releases are in-progress to include this fix. Ongoing vote threads: |
Motivation
Upgrade to async-http-client 2.12.4 which contains a fix for CVE-2024-53990. See https://lists.apache.org/thread/fpg465pxytqkxbs57h7p3mckn9dwh3zq for more details.
Modifications
com.sun.activation:javax.activation
withcom.sun.activation:jakarta.activation
Documentation
doc
doc-required
doc-not-needed
doc-complete