-
Notifications
You must be signed in to change notification settings - Fork 1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[UNDERTOW-2391] CVE-2023-5685 bump xnio to bring in fix for the CVE #1592
Conversation
@smmathews-cision-us thanks for bringing this into attention. |
Unfortunately tests are failing, I'll need to investigate before merging this one |
Hello, @fl4via, do you think it would be unsafe for undertow consumers to exclude and replace xnio in pom as transitive dependency, e.g.:
I'm asking, because we have a vulnerability report pending on undertow on that and need to deal with it. |
Hi @romabaz ! I spent the past two weeks investigating this regression and testing a fix for XNIO in internal labs to make sure the final solution to this regression would not cause other regressions of any sorts, specially taking into consideration Undertow and its interaction with WildFly/JBoss Remoting corner scenarios. That's why this PR has been "stalled". |
Signed-off-by: Flavia Rainone <frainone@redhat.com>
@fl4via , thank you for your prompt response! |
Bumps xnio from 3.8.8.Final to 3.8.14.Final, which is the latest version and the first version to fix CVE-2023-5685
jira ticket is https://issues.redhat.com/browse/UNDERTOW-2391