Skip to content

Potential security vulnerability with Netty dependency #2385

@Antti-Paladin

Description

@Antti-Paladin

Issue Type:

  • Bug report
  • Feature request

What happened:
There is a security vulnerability CVE-2020-11612 which concerns Netty 4.1.x before 4.1.46, and thus might affect Linkerd too (as of today the Netty version used seems to be 4.1.31 in master).

What you expected to happen:
It could be investigated if this causes a security vulnerability in Linkerd too. If so (and feasible), could update the Netty dependency to a version without the vulnerability.

Environment:

  • linkerd version: 1.7.1, but I believe this manifests with all versions using Netty 4.1.x

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions