-
Notifications
You must be signed in to change notification settings - Fork 3.6k
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
[fix][sec] Upgrade async-http-client to 2.12.4 to address CVE-2024-53990 #23732
Conversation
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## master #23732 +/- ##
============================================
+ Coverage 73.57% 74.40% +0.83%
- Complexity 32624 35097 +2473
============================================
Files 1877 1945 +68
Lines 139502 147510 +8008
Branches 15299 16280 +981
============================================
+ Hits 102638 109761 +7123
- Misses 28908 29273 +365
- Partials 7956 8476 +520
Flags with carried forward coverage won't be shown. Click here to find out more. |
(apache#23732) (cherry picked from commit 9a7269a) (cherry picked from commit 9c04964)
(apache#23732) (cherry picked from commit 9a7269a) (cherry picked from commit 9c04964)
The releases are in-progress to include this fix. Ongoing vote threads: |
Motivation
Upgrade to async-http-client 2.12.4 which contains a fix for CVE-2024-53990. See https://lists.apache.org/thread/fpg465pxytqkxbs57h7p3mckn9dwh3zq for more details.
Modifications
com.sun.activation:javax.activation
withcom.sun.activation:jakarta.activation
Documentation
doc
doc-required
doc-not-needed
doc-complete