diff --git a/CHANGES.txt b/CHANGES.txt index e2ccc53785..fdf045de45 100644 --- a/CHANGES.txt +++ b/CHANGES.txt @@ -1,3 +1,7 @@ +3.11.3 +Merged from 2.1 + * CVE-2017-5929 Security vulnerability in Logback warning in NEWS.txt (CASSANDRA-14183) + 3.11.2 * Fix ReadCommandTest (CASSANDRA-14234) * Remove trailing period from latency reports at keyspace level (CASSANDRA-14233) diff --git a/NEWS.txt b/NEWS.txt index fb1dafe96e..445623e96f 100644 --- a/NEWS.txt +++ b/NEWS.txt @@ -18,6 +18,15 @@ CASSANDRA-14092.txt file. If you use or plan to use very large TTLS (10 to 20 years), read CASSANDRA-14092.txt for more information. +PLEASE READ: CVE-2017-5929 LOGBACK BEFORE 1.2.0 SERIALIZATION VULNERABILITY +------------------------------------------------------------------ +QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the +SocketServer and ServerSocketReceiver components. + +Logback has not been upgraded to avoid breaking deployments and customizations +based on older versions. If you are using vulnerable components you will need +to upgrade to a newer version of Logback or stop using the vulnerable components. + GENERAL UPGRADING ADVICE FOR ANY VERSION ========================================