We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Project board link
We are using cassandra-reaper version 3.2.0 in our product. Recently we did Blackduck security scan and following issue was reported for reaper.
Component name : jersey's jersey
Component version name : 2.33
CVE : CVE-2021-28168 (BDSA-2021-1123) - score 5.5
Can you please help us to confirm -
if version 3.2.0 is vulnerable for these CVE ? if yes, in which version the fix would be available ?
┆Issue is synchronized with this Jira Story by Unito ┆Issue Number: REAP-80
The text was updated successfully, but these errors were encountered:
We don't have a fix version for this yet.
Sorry, something went wrong.
@adejanovski Any idea if version 3.2.0 is vulnerable with this CVE ?
Update pom.xml
53ebd09
Fixes #1248 Upgrade jersey to 2.34 in order to fix CVE-2021-28168
Most probably, yes. I've created a PR which upgrades jersey to v2.34 which contains the fix. Let's see how CI goes.
Hi @adejanovski Which version of reaper will have this fix ?
adejanovski
Successfully merging a pull request may close this issue.
Project board link
We are using cassandra-reaper version 3.2.0 in our product.
Recently we did Blackduck security scan and following issue was reported for reaper.
Component name : jersey's jersey
Component version name : 2.33
CVE :
CVE-2021-28168 (BDSA-2021-1123) - score 5.5
Can you please help us to confirm -
if version 3.2.0 is vulnerable for these CVE ?
if yes, in which version the fix would be available ?
┆Issue is synchronized with this Jira Story by Unito
┆Issue Number: REAP-80
The text was updated successfully, but these errors were encountered: