Merge branch 'cassandra-2.2' into cassandra-3.0

This commit is contained in:
Ariel Weisberg 2018-02-14 13:29:17 -05:00
commit 2461187c0e
2 changed files with 13 additions and 0 deletions

View File

@ -1,3 +1,7 @@
3.0.17
Merged from 2.1:
* CVE-2017-5929 Security vulnerability in Logback warning in NEWS.txt (CASSANDRA-14183)
3.0.16
* Fix unit test failures in ViewComplexTest (CASSANDRA-14219)
* Add MinGW uname check to start scripts (CASSANDRA-12940)

View File

@ -18,6 +18,15 @@ CASSANDRA-14092.txt file.
If you use or plan to use very large TTLS (10 to 20 years), read CASSANDRA-14092.txt
for more information.
PLEASE READ: CVE-2017-5929 LOGBACK BEFORE 1.2.0 SERIALIZATION VULNERABILITY
------------------------------------------------------------------
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the
SocketServer and ServerSocketReceiver components.
Logback has not been upgraded to avoid breaking deployments and customizations
based on older versions. If you are using vulnerable components you will need
to upgrade to a newer version of Logback or stop using the vulnerable components.
GENERAL UPGRADING ADVICE FOR ANY VERSION
========================================