You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Comments on closed issues are hard for our team to see.
If you need more assistance, please open a new issue that references this one.
If you wish to keep having a conversation with other community members under this issue feel free to do so.
Describe the bug
I think that aws-sdk isnt vulnerable, since a simliar library, azure SDK isnt (using netty as client only):
Azure/azure-sdk-for-java#37198
but can you confirm this?
Expected Behavior
no cve
Current Behavior
CVE warning
Reproduction Steps
Run owasp-dependency check
Possible Solution
Upgrade netty to 4.1.100:
https://netty.io/news/2023/10/10/4-1-100-Final.html
Additional Information/Context
No response
AWS Java SDK version used
software.amazon.awssdk/bom/2.21.2
JDK version used
latest 17
Operating System and version
linux from scratch
The text was updated successfully, but these errors were encountered: