Reputation: 9
We need this release done in order to migrate to version 4.1.4 and have the fix for Security Vulnerability (Upgrade snappy java library) https://issues.apache.org/jira/browse/CASSANDRA-18878
We cannot move to version 5 of Cassandra as is still a Beta and is not allowed by our management to use Beta Versions while 4.1.3 still have this Vulnerability Issue inside it. So we are stuck => either we have a new Cassandra 4.1.4 released or you Release Cassandra 5.0 but make it official.
We created a build based on this cassandra 4.1.4 branch for testing on linux GitHub - apache/cassandra at cassandra-4.1 and the vulnerability was not there. We expect the official release so we can reference
Upvotes: 0
Views: 294
Reputation: 57748
Circling back to this; in case you're not checking the mailing list, a release of Apache Cassandra® 4.1.4 is currently up for a vote. If it passes, 4.1.4 should be released next week sometime.
Here's a list of what is included in that build, which includes CASSANDRA-18878:
https://github.com/apache/cassandra/blob/4.1.4-tentative/CHANGES.txt
Upvotes: 0