NIFI-9342 Upgraded to Netty 3.10.6 and 4.1.69

- Replaced Netty 3.6.9 and 3.7.1 with 3.10.6
- Replaced Netty 4.1 with 4.1.69

Signed-off-by: Pierre Villard <pierre.villard.fr@gmail.com>

This closes #5490.
This commit is contained in:
exceptionfactory 2021-10-27 20:52:59 -05:00 committed by Pierre Villard
parent 3114bdb701
commit 60d6d469bf
No known key found for this signature in database
GPG Key ID: F92A93B30C07C6D5
27 changed files with 172 additions and 29 deletions

View File

@ -40,7 +40,7 @@
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-handler</artifactId>
<version>4.1.65.Final</version>
<version>${netty.4.version}</version>
<scope>test</scope>
</dependency>
</dependencies>

View File

@ -48,6 +48,11 @@
<artifactId>zookeeper</artifactId>
<version>3.4.14</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>${netty.3.version}</version>
</dependency>
</dependencies>
</dependencyManagement>
<dependencies>

View File

@ -85,6 +85,17 @@
<artifactId>commons-compress</artifactId>
<version>1.21</version>
</dependency>
<!-- Override Netty 4 -->
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-handler</artifactId>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-transport-native-epoll</artifactId>
<version>${netty.4.version}</version>
</dependency>
</dependencies>
</dependencyManagement>

View File

@ -90,6 +90,23 @@
<artifactId>zookeeper</artifactId>
<version>3.4.14</version>
</dependency>
<!-- Override Netty 3 -->
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>${netty.3.version}</version>
</dependency>
<!-- Override Netty Transport 4 -->
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-transport</artifactId>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-transport-native-epoll</artifactId>
<version>${netty.4.version}</version>
</dependency>
</dependencies>
</dependencyManagement>

View File

@ -93,6 +93,22 @@ language governing permissions and limitations under the License. -->
<artifactId>nifi-ssl-context-service</artifactId>
<scope>test</scope>
</dependency>
<!-- Override Netty 4 -->
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-transport</artifactId>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-codec-http</artifactId>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-handler</artifactId>
<version>${netty.4.version}</version>
</dependency>
</dependencies>
<build>

View File

@ -138,6 +138,12 @@ language governing permissions and limitations under the License. -->
<artifactId>nifi-standard-record-utils</artifactId>
<version>1.15.0-SNAPSHOT</version>
</dependency>
<!-- Override Netty 3 -->
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>${netty.3.version}</version>
</dependency>
</dependencies>
<build>

View File

@ -26,7 +26,7 @@
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-handler</artifactId>
<version>4.1.63.Final</version>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>org.apache.nifi</groupId>

View File

@ -26,17 +26,16 @@
<modules>
<module>nifi-avro-record-utils</module>
<module>nifi-standard-record-utils</module>
<module>nifi-hadoop-record-utils</module>
<module>nifi-mock-record-utils</module>
<module>nifi-hadoop-record-utils</module>
<module>nifi-mock-record-utils</module>
</modules>
<dependencyManagement>
<dependencies>
<dependency>
<!-- Explicitly force Netty to 3.7.1 due to CVE-2014-0193 -->
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>3.7.1.Final</version>
<version>${netty.3.version}</version>
</dependency>
<!-- Override commons-compress -->
<dependency>

View File

@ -35,6 +35,18 @@
<artifactId>nifi-flume-processors</artifactId>
<version>1.15.0-SNAPSHOT</version>
</dependency>
<!-- Override Netty 3 -->
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>${netty.3.version}</version>
</dependency>
<!-- Override Netty 4 -->
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-all</artifactId>
<version>${netty.4.version}</version>
</dependency>
</dependencies>
</dependencyManagement>
</project>

View File

@ -647,10 +647,9 @@
<version>3.6</version>
</dependency>
<dependency>
<!-- Explicitly force Netty to 3.7.1 due to CVE-2014-0193 -->
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>3.7.1.Final</version>
<version>${netty.3.version}</version>
</dependency>
</dependencies>
</dependencyManagement>

View File

@ -114,5 +114,11 @@
<groupId>org.apache.nifi</groupId>
<artifactId>nifi-mock</artifactId>
</dependency>
<!-- Override Netty 4 -->
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-all</artifactId>
<version>${netty.4.version}</version>
</dependency>
</dependencies>
</project>

View File

@ -118,6 +118,12 @@
<artifactId>gremlin-driver</artifactId>
<version>${gremlin.version}</version>
</dependency>
<!-- Override Netty 4 -->
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-all</artifactId>
<version>${netty.4.version}</version>
</dependency>
</dependencies>
<build>

View File

@ -39,6 +39,12 @@
<artifactId>jackson-databind</artifactId>
<version>${jackson.version}</version>
</dependency>
<!-- Override Netty 4 -->
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-all</artifactId>
<version>${netty.4.version}</version>
</dependency>
</dependencies>
</dependencyManagement>
</project>

View File

@ -29,10 +29,9 @@
<dependencyManagement>
<dependencies>
<dependency>
<!-- Explicitly force Netty to 3.7.1 due to CVE-2014-0193 -->
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>3.7.1.Final</version>
<version>${netty.3.version}</version>
</dependency>
<!-- Override commons-io:2.5 from hadoop libraries -->
<dependency>

View File

@ -40,10 +40,9 @@
<dependencyManagement>
<dependencies>
<dependency>
<!-- Explicitly force Netty to 3.7.1 due to CVE-2014-0193 -->
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>3.7.1.Final</version>
<version>${netty.3.version}</version>
</dependency>
<!-- Override snapshot versions of javax.el -->
<dependency>
@ -111,6 +110,22 @@
<artifactId>zookeeper</artifactId>
<version>3.4.14</version>
</dependency>
<!-- Override Netty 4 -->
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-buffer</artifactId>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-common</artifactId>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-all</artifactId>
<version>${netty.4.version}</version>
</dependency>
</dependencies>
</dependencyManagement>

View File

@ -86,10 +86,9 @@
<version>1.15.0-SNAPSHOT</version>
</dependency>
<dependency>
<!-- Explicitly force Netty to 3.7.1 due to CVE-2014-0193 -->
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>3.7.1.Final</version>
<version>${netty.3.version}</version>
</dependency>
</dependencies>
</dependencyManagement>

View File

@ -39,10 +39,9 @@
<version>1.15.0-SNAPSHOT</version>
</dependency>
<dependency>
<!-- Explicitly force Netty to 3.6.9 due to CVE-2014-0193 -->
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>3.6.9.Final</version>
<version>${netty.3.version}</version>
</dependency>
<!-- Override commons-io:2.4 from kite -->
<dependency>

View File

@ -32,12 +32,11 @@
<module>nifi-parquet-nar</module>
</modules>
<dependencyManagement>
<!-- Explicitly force Netty to 3.6.9 due to CVE-2014-0193 -->
<dependencies>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>3.6.9.Final</version>
<version>${netty.3.version}</version>
</dependency>
<!-- Override commons-io:2.5 -->
<dependency>

View File

@ -45,10 +45,9 @@
<version>1.15.0-SNAPSHOT</version>
</dependency>
<dependency>
<!-- Explicitly force Netty to 3.6.9 due to CVE-2014-0193 -->
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>3.6.9.Final</version>
<version>${netty.3.version}</version>
</dependency>
</dependencies>
</dependencyManagement>

View File

@ -35,6 +35,47 @@
<artifactId>commons-io</artifactId>
<version>2.10.0</version>
</dependency>
<!-- Override Netty 4 -->
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-transport</artifactId>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-buffer</artifactId>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-codec</artifactId>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-common</artifactId>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-handler</artifactId>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-resolver</artifactId>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-transport-native-epoll</artifactId>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-transport-native-unix-common</artifactId>
<version>${netty.4.version}</version>
</dependency>
</dependencies>
</dependencyManagement>
</project>

View File

@ -59,10 +59,9 @@
<version>1.19.1</version>
</dependency>
<dependency>
<!-- Explicitly force Netty to 3.7.1 due to CVE-2014-0193 -->
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>3.7.1.Final</version>
<version>${netty.3.version}</version>
</dependency>
<!-- Override zookeeper -->
<dependency>

View File

@ -62,7 +62,7 @@
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-buffer</artifactId>
<version>4.1.65.Final</version>
<version>${netty.4.version}</version>
</dependency>
</dependencies>
</project>

View File

@ -83,10 +83,9 @@
<version>${hadoop.version}</version>
</dependency>
<dependency>
<!-- Explicitly force Netty to 3.6.9 due to CVE-2014-0193 -->
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>3.6.9.Final</version>
<version>${netty.3.version}</version>
</dependency>
<!-- Override commons-io:2.4 from hbase-client -->
<dependency>

View File

@ -53,10 +53,9 @@
<dependencyManagement>
<dependencies>
<dependency>
<!-- Explicitly force Netty to 3.6.9 due to CVE-2014-0193 -->
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>3.6.9.Final</version>
<version>${netty.3.version}</version>
</dependency>
<!-- Override commons-io:2.4 from hbase-client -->
<dependency>

View File

@ -48,6 +48,17 @@
<artifactId>mockito-core</artifactId>
<scope>test</scope>
</dependency>
<!-- Override Netty 4 -->
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-transport</artifactId>
<version>${netty.4.version}</version>
</dependency>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-transport-native-unix-common</artifactId>
<version>${netty.4.version}</version>
</dependency>
</dependencies>
</project>

View File

@ -53,10 +53,9 @@
</exclusions>
</dependency>
<dependency>
<!-- Explicitly force Netty to 3.7.1 due to CVE-2014-0193 -->
<groupId>io.netty</groupId>
<artifactId>netty</artifactId>
<version>3.7.1.Final</version>
<version>${netty.3.version}</version>
</dependency>
</dependencies>
</dependencyManagement>

View File

@ -112,6 +112,8 @@
<jersey.version>2.33</jersey.version>
<logback.version>1.2.6</logback.version>
<mockito.version>3.11.2</mockito.version>
<netty.3.version>3.10.6.Final</netty.3.version>
<netty.4.version>4.1.69.Final</netty.4.version>
</properties>
<repositories>