Upgrade vendored beam-vendor-grpc-1_54_0 to eliminate vulnerability from shaded Netty #29861
Closed
1 of 16 tasks
Labels
Milestone
What happened?
The beam-vendor-grpc-1_54_0 shades a vulnerable Netty version 4.1.87.Final
It brings CVE-2023-44487 Base Score: 7.5 High
JFrog Xray recommends updating it at least to version 4.1.100.Final
Could you please fix this vulnerability in the shaded jar and also let us know when you are planning to release this?
https://github.com/apache/beam/blob/master/buildSrc/src/main/groovy/org/apache/beam/gradle/GrpcVendoring_1_54_0.groovy#L46
Issue Priority
Priority: 2 (default / most bugs should be filed as P2)
Issue Components
The text was updated successfully, but these errors were encountered: