[fix][sec] Upgrade Jetty to 9.4.57.v20241219 to mitigate CVE-2024-6763 - #24232
Conversation
|
hello , I am a new developer for pulsar, our product start to use pulsar, which replace kafka in serverless env. I can learn your pr. our other product has upgraded jetty to 9.4.57.v20241219. this pr is good. |
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## master #24232 +/- ##
============================================
+ Coverage 73.57% 74.19% +0.62%
+ Complexity 32624 32557 -67
============================================
Files 1877 1866 -11
Lines 139502 144900 +5398
Branches 15299 16549 +1250
============================================
+ Hits 102638 107515 +4877
+ Misses 28908 28871 -37
- Partials 7956 8514 +558
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
apache#24232) (cherry picked from commit 611dc3f) (cherry picked from commit 1ac0898)
apache#24232) (cherry picked from commit 611dc3f) (cherry picked from commit 1ac0898)
apache#24232) (cherry picked from commit 611dc3f) (cherry picked from commit b3c6f2a)
apache#24232) (cherry picked from commit 611dc3f) (cherry picked from commit b3c6f2a)
apache#24232) (cherry picked from commit 611dc3f) (cherry picked from commit b3c6f2a)
|
Addresses CVE-2024-13009 too. |
apache#24232) (cherry picked from commit 611dc3f)
This is intentional, this is the "Unsupported when Assigned" behavior (a CVE thing), as Jetty 9 is EOL (End of Life)
If you still need |
Fixes #24114
Motivation & Modifications
Upgrade Jetty to 9.4.57.v20241219 to address CVE-2024-6763
Jetty 9.4.57.v20241219 contains backported CVE-2024-6763 fix in jetty/jetty.project#12532 although it's not explicitly mentioned and most security scanners don't yet contain the information that it's been addressed in 9.4.57.
More details:
Note: The backport is a partial mitigation and Jetty 9.4.57 will continue to be marked as vulnerable. There's a discussion and explanation here: https://gitlab.eclipse.org/security/cve-assignement/-/issues/25#note_2968611
Documentation
docdoc-requireddoc-not-neededdoc-complete