Skip to content

Resolve Netty CVEs for Java Lambda Layer #2948

Description

@sharvath-newrelic

Description

A customer has reported several vulnerabilities via an AWS inspector security scan:

These vulnerabilities can be resolved by bumping Netty to 4.1.135.Final which was done initially in AWS with version 2.46.5. We will want to bump the amazon.awssdk dependency to use the aforementioned version (or more current) in our Java AWS Lambda repo, followed by bumping Java AWS Lambda dependency version in the New Relic Lambda Layer.

Metadata

Metadata

Assignees

Labels

2Story Point Estimate

Type

No fields configured for Task.

Projects

Status
Needs Review

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions