There is a vulnerability in Netty Project 4.1.31.Final,upgrade recommended
envgap__alibaba__Sentinel-1998
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
fca70646ad17b592e2116577c8522c99648c20a0- Manifest
sentinel-cluster/pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
alibaba/Sentinel #1998 · read the original issue
https://github.com/alibaba/Sentinel/blob/1f4614c0d4c5e966de1cd9f6715c8220937ef2a9/sentinel-cluster/pom.xml#L19 CVE-2019-20445 CVE-2019-20444 CVE-2020-11612 CVE-2019-9512 Recommended upgrade version:1:4.1.48-1
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]