Skip to content

KNOX-3366:Upgrade Mina-core to 2.2.8#1285

Open
devaspatikrishnatri wants to merge 1 commit into
apache:masterfrom
devaspatikrishnatri:KNOX-3366
Open

KNOX-3366:Upgrade Mina-core to 2.2.8#1285
devaspatikrishnatri wants to merge 1 commit into
apache:masterfrom
devaspatikrishnatri:KNOX-3366

Conversation

@devaspatikrishnatri

Copy link
Copy Markdown

(It is very important that you created an Apache Knox JIRA for this change and that the PR title/commit message includes the Apache Knox JIRA ID!)

KNOX-3366 - Upgrade mina-core to 2.2.8

What changes were proposed in this pull request?

Upgrade mina-core to 2.2.8 to target CVEs.
CVE-2026-47065: Critical Deserialization Allow-list Bypass via resolveProxyClass - ZDRES-232
CVE-2026-47321: Unbounded Decompression Amplification DoS in Apache Mina Zlib.inflate - ZDRES-231
https://mina.apache.org/mina-project/news

How was this patch tested?

Built Locally , relying on precommits.

Integration Tests

No additional tests added , as this is a minor change.

Please review Knox Contributing Process before opening a pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant