-
Notifications
You must be signed in to change notification settings - Fork 992
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
netty-handler
4.1.x (SslHandler
) flagged as vulnerable dependency
#1845
Comments
No this is neither of those two. |
(I am sending more information in private mail) |
The problem was an insecure default configuration in netty-handler as discussed in netty/netty#10362 |
netty-handler
4.1.x (SslHandler
) flagged as vulnerable dependency
Thanks for reaching out. Netty's There's currently no netty 5.0 release available hence we cannot upgrade to a non-affected version. In any case, that wouldn't change anything on the experienced security features in Lettuce, it would only make the dependency scanner happier. |
Bug Report
Well policy says that for security vulnerabilities we should NOT give away any details.
So I would only say that the enterprise grade code scan engine we are using in our corp.
reports a security "vulnerability" in a third party that you are using...
I tried searching for a corresponding fixed bug report in your project but had no luck.
Reading some of your code around potential vulnerable use ;
I could not determine if vulnerability is effective or not
(though I incline to believe it is not).
I'll be waiting for your contact back.
Environment
at least lettuce-core [5.3.1 to 6.1.x] are using potentially vulnerable code
Possible Solution
No upgraded release available yet.
You may need to work around.
Additional context
MITM
The text was updated successfully, but these errors were encountered: