mirror of https://github.com/apache/cassandra
Merge branch 'cassandra-3.0' into cassandra-3.11
This commit is contained in:
commit
630c18eb38
|
|
@ -1,3 +1,7 @@
|
|||
3.11.3
|
||||
Merged from 2.1
|
||||
* CVE-2017-5929 Security vulnerability in Logback warning in NEWS.txt (CASSANDRA-14183)
|
||||
|
||||
3.11.2
|
||||
* Fix ReadCommandTest (CASSANDRA-14234)
|
||||
* Remove trailing period from latency reports at keyspace level (CASSANDRA-14233)
|
||||
|
|
|
|||
9
NEWS.txt
9
NEWS.txt
|
|
@ -18,6 +18,15 @@ CASSANDRA-14092.txt file.
|
|||
If you use or plan to use very large TTLS (10 to 20 years), read CASSANDRA-14092.txt
|
||||
for more information.
|
||||
|
||||
PLEASE READ: CVE-2017-5929 LOGBACK BEFORE 1.2.0 SERIALIZATION VULNERABILITY
|
||||
------------------------------------------------------------------
|
||||
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the
|
||||
SocketServer and ServerSocketReceiver components.
|
||||
|
||||
Logback has not been upgraded to avoid breaking deployments and customizations
|
||||
based on older versions. If you are using vulnerable components you will need
|
||||
to upgrade to a newer version of Logback or stop using the vulnerable components.
|
||||
|
||||
GENERAL UPGRADING ADVICE FOR ANY VERSION
|
||||
========================================
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue