Our spring boot (cloud) application uses rx-netty, whose version is 0.4.20. And it sets netty and its components to version 4.1.5.Final.
Currently our security auditing system found that the current netty-codec version (4.1.52.Final) is vulnerable and suggested us to upgrade to version 4.1.68+.
I tried to lock netty-codec in pom.xml to 4.1.68.Final, but then I found that other netty components like netty-buffer or netty-handler still stay at 4.1.52.
I want to know:
- Should I keep all the netty components at the same version?
- What is the right way to upgrade individual vulnerable components?
Thanks
Update:
mvn dependency:tree
...
[INFO] +- io.reactivex:rxnetty-contexts:jar:0.4.20:compile
[INFO] +- io.reactivex:rxnetty-servo:jar:0.4.20:compile
[INFO] | \- com.netflix.servo:servo-core:jar:0.12.21:runtime
[INFO] +- io.reactivex:rxnetty:jar:0.4.20:compile
[INFO] | +- io.netty:netty-codec-http:jar:4.1.69.Final:runtime
[INFO] | | +- io.netty:netty-common:jar:4.1.69.Final:runtime
[INFO] | | +- io.netty:netty-buffer:jar:4.1.52.Final:runtime
[INFO] | | +- io.netty:netty-transport:jar:4.1.52.Final:runtime
[INFO] | | \- io.netty:netty-codec:jar:4.1.52.Final:runtime
[INFO] | +- io.netty:netty-handler:jar:4.1.69.Final:runtime
[INFO] | | \- io.netty:netty-resolver:jar:4.1.52.Final:runtime
[INFO] | +- io.netty:netty-transport-native-epoll:jar:4.1.69.Final:runtime
[INFO] | | \- io.netty:netty-transport-native-unix-common:jar:4.1.52.Final:runtime
...