ZooKeeper 3.9.4 - Vulnerability Patch Status
============================================

This package has been patched to address the following vulnerabilities:

FIXED:
- GHSA-3p6m-385q-pgmj: netty-codec upgraded from 4.1.119.Final to 4.1.125.Final
- GHSA-qp4g-569p-2xwl: jetty-http upgraded from 9.4.57.v20241219 to 12.0.12
- GHSA-25qh-j22f-pwp8: logback-core upgraded from 1.3.15 to 1.5.19

Jetty components updated:
- jetty-http: 9.4.57 → 12.0.12 ✓ (MAIN VULNERABILITY FIXED)
- jetty-security: 9.4.57 → 12.0.12 ✓
- jetty-util: 9.4.57 → 12.0.12 ✓
- jetty-server: 9.4.57 → 12.0.12 ✓
- jetty-util-ajax: 9.4.57 → 12.0.12 ✓
- jetty-io: 9.4.57 → 12.0.12 ✓
- jetty-ee8-servlet: 12.0.12 (NEW - fixes AdminServer ClassNotFoundException)

Logback components updated:
- logback-core: 1.3.x → 1.5.19 ✓
- logback-classic: 1.3.x → 1.5.19 ✓


Patch applied: $(date)
Package version: 3.9.4-r3
