-
Notifications
You must be signed in to change notification settings - Fork 3.7k
[fix][sec] Upgrade Jetty to 9.4.57.v20241219 to mitigate CVE-2024-6763 #24232
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
hello , I am a new developer for pulsar, our product start to use pulsar, which replace kafka in serverless env. I can learn your pr. our other product has upgraded jetty to 9.4.57.v20241219. this pr is good. |
wangchao316
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## master #24232 +/- ##
============================================
+ Coverage 73.57% 74.19% +0.62%
+ Complexity 32624 32557 -67
============================================
Files 1877 1866 -11
Lines 139502 144900 +5398
Branches 15299 16549 +1250
============================================
+ Hits 102638 107515 +4877
+ Misses 28908 28871 -37
- Partials 7956 8514 +558
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
apache#24232) (cherry picked from commit 611dc3f) (cherry picked from commit 1ac0898)
apache#24232) (cherry picked from commit 611dc3f) (cherry picked from commit 1ac0898)
apache#24232) (cherry picked from commit 611dc3f) (cherry picked from commit b3c6f2a)
apache#24232) (cherry picked from commit 611dc3f) (cherry picked from commit b3c6f2a)
apache#24232) (cherry picked from commit 611dc3f) (cherry picked from commit b3c6f2a)
|
Addresses CVE-2024-13009 too. |
apache#24232) (cherry picked from commit 611dc3f)
This is intentional, this is the "Unsupported when Assigned" behavior (a CVE thing), as Jetty 9 is EOL (End of Life)
If you still need |
Fixes #24114
Motivation & Modifications
Upgrade Jetty to 9.4.57.v20241219 to address CVE-2024-6763
Jetty 9.4.57.v20241219 contains backported CVE-2024-6763 fix in jetty/jetty.project#12532 although it's not explicitly mentioned and most security scanners don't yet contain the information that it's been addressed in 9.4.57.
More details:
Note: The backport is a partial mitigation and Jetty 9.4.57 will continue to be marked as vulnerable. There's a discussion and explanation here: https://gitlab.eclipse.org/security/cve-assignement/-/issues/25#note_2968611
Documentation
docdoc-requireddoc-not-neededdoc-complete