Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[UNDERTOW-2391] bump xnio to bring in fix for CVE-2023-5685 #1592

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

smmathews-cision-us
Copy link

Bumps xnio from 3.8.8.Final to 3.8.14.Final, which is the latest version and the first version to fix CVE-2023-5685

jira ticket is https://issues.redhat.com/browse/UNDERTOW-2391

@romabaz
Copy link

romabaz commented May 17, 2024

@smmathews-cision-us thanks for bringing this into attention.

Signed-off-by: Flavia Rainone <frainone@redhat.com>
@fl4via fl4via changed the title bump xnio to bring in fix for CVE-2023-5685 [UNDERTOW-2391] bump xnio to bring in fix for CVE-2023-5685 May 20, 2024
@fl4via fl4via added next release This PR will be merged before next release or has already been merged (for payload double check) waiting CI check Ready to be merged but waiting for CI check dependency upgrade Pull requests that update a dependency file failed CI Introduced new regession(s) during CI check labels May 20, 2024
@fl4via
Copy link
Member

fl4via commented May 20, 2024

Unfortunately tests are failing, I'll need to investigate before merging this one

@fl4via fl4via removed the waiting CI check Ready to be merged but waiting for CI check label May 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependency upgrade Pull requests that update a dependency file failed CI Introduced new regession(s) during CI check next release This PR will be merged before next release or has already been merged (for payload double check)
Projects
None yet
3 participants