Skip to content

Old Netty version for Appdistribution #7712

@Shusek

Description

@Shusek

[READ] Step 1: Are you in the right place?

Yes

[REQUIRED] Step 2: Describe your environment

  • Android Studio version: \Android Studio Otter 3 Feature Drop | 2025.2.3
  • Firebase Component: App Distribution
  • Component version: 34.8.0 BOM
    appDistribution Gradle 5.2.0

[REQUIRED] Step 3: Describe the problem

Security scanners detected a vulnerability inside CVE-2025-58057 com.google.firebase.appdistribution.gradle.plugin.*. Suggested update to newer version.

Steps to reproduce:

Relevant Code:

./gradlew buildEnvironment          
|         +--- io.grpc:grpc-netty:1.69.1
|         |    +--- io.grpc:grpc-api:1.69.1 (*)
|         |    +--- io.netty:netty-codec-http2:4.1.110.Final

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions