Skip to content

Commit 7c58be4

Browse files
lhotariStevenLuMT
authored andcommitted
Upgrade Jetty to 9.4.57.v20241219 to address CVE-2024-6763 (#4600)
### Motivation & Changes Upgrade Jetty to 9.4.57.v20241219 to address CVE-2024-6763 Jetty 9.4.57.v20241219 contains backported CVE-2024-6763 fix in jetty/jetty.project#12532 although it's not explicitly mentioned and most security scanners don't yet contain the information that it's been addressed in 9.4.57. More details: * jetty/jetty.project#12630 * https://github.com/jetty/jetty.project/releases/tag/jetty-9.4.57.v20241219 Note: The backport is a partial mitigation and Jetty 9.4.57 will continue to be marked as vulnerable. There's a discussion and explanation here: https://gitlab.eclipse.org/security/cve-assignement/-/issues/25#note_2968611 (cherry picked from commit 99eb63a)
1 parent 05f2d11 commit 7c58be4

File tree

5 files changed

+33
-33
lines changed

5 files changed

+33
-33
lines changed

bookkeeper-dist/src/main/resources/LICENSE-all.bin.txt

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -267,14 +267,14 @@ Apache Software License, Version 2.
267267
- lib/org.apache.zookeeper-zookeeper-3.9.3.jar [21]
268268
- lib/org.apache.zookeeper-zookeeper-jute-3.9.3.jar [21]
269269
- lib/org.apache.zookeeper-zookeeper-3.9.3-tests.jar [21]
270-
- lib/org.eclipse.jetty-jetty-http-9.4.53.v20231009.jar [22]
271-
- lib/org.eclipse.jetty-jetty-io-9.4.53.v20231009.jar [22]
272-
- lib/org.eclipse.jetty-jetty-security-9.4.53.v20231009.jar [22]
273-
- lib/org.eclipse.jetty-jetty-server-9.4.53.v20231009.jar [22]
274-
- lib/org.eclipse.jetty-jetty-servlet-9.4.53.v20231009.jar [22]
275-
- lib/org.eclipse.jetty-jetty-util-9.4.53.v20231009.jar [22]
276-
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.53.v20231009.jar [22]
277-
- lib/org.rocksdb-rocksdbjni-7.10.2.jar [23]
270+
- lib/org.eclipse.jetty-jetty-http-9.4.57.v20241219.jar [22]
271+
- lib/org.eclipse.jetty-jetty-io-9.4.57.v20241219.jar [22]
272+
- lib/org.eclipse.jetty-jetty-security-9.4.57.v20241219.jar [22]
273+
- lib/org.eclipse.jetty-jetty-server-9.4.57.v20241219.jar [22]
274+
- lib/org.eclipse.jetty-jetty-servlet-9.4.57.v20241219.jar [22]
275+
- lib/org.eclipse.jetty-jetty-util-9.4.57.v20241219.jar [22]
276+
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.57.v20241219.jar [22]
277+
- lib/org.rocksdb-rocksdbjni-9.9.3.jar [23]
278278
- lib/com.beust-jcommander-1.82.jar [24]
279279
- lib/com.yahoo.datasketches-memory-0.8.3.jar [25]
280280
- lib/com.yahoo.datasketches-sketches-core-0.8.3.jar [25]

bookkeeper-dist/src/main/resources/LICENSE-server.bin.txt

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -267,14 +267,14 @@ Apache Software License, Version 2.
267267
- lib/org.apache.zookeeper-zookeeper-3.9.3.jar [21]
268268
- lib/org.apache.zookeeper-zookeeper-jute-3.9.3.jar [21]
269269
- lib/org.apache.zookeeper-zookeeper-3.9.3-tests.jar [21]
270-
- lib/org.eclipse.jetty-jetty-http-9.4.53.v20231009.jar [22]
271-
- lib/org.eclipse.jetty-jetty-io-9.4.53.v20231009.jar [22]
272-
- lib/org.eclipse.jetty-jetty-security-9.4.53.v20231009.jar [22]
273-
- lib/org.eclipse.jetty-jetty-server-9.4.53.v20231009.jar [22]
274-
- lib/org.eclipse.jetty-jetty-servlet-9.4.53.v20231009.jar [22]
275-
- lib/org.eclipse.jetty-jetty-util-9.4.53.v20231009.jar [22]
276-
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.53.v20231009.jar [22]
277-
- lib/org.rocksdb-rocksdbjni-7.10.2.jar [23]
270+
- lib/org.eclipse.jetty-jetty-http-9.4.57.v20241219.jar [22]
271+
- lib/org.eclipse.jetty-jetty-io-9.4.57.v20241219.jar [22]
272+
- lib/org.eclipse.jetty-jetty-security-9.4.57.v20241219.jar [22]
273+
- lib/org.eclipse.jetty-jetty-server-9.4.57.v20241219.jar [22]
274+
- lib/org.eclipse.jetty-jetty-servlet-9.4.57.v20241219.jar [22]
275+
- lib/org.eclipse.jetty-jetty-util-9.4.57.v20241219.jar [22]
276+
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.57.v20241219.jar [22]
277+
- lib/org.rocksdb-rocksdbjni-9.9.3.jar [23]
278278
- lib/com.beust-jcommander-1.82.jar [24]
279279
- lib/com.yahoo.datasketches-memory-0.8.3.jar [25]
280280
- lib/com.yahoo.datasketches-sketches-core-0.8.3.jar [25]

bookkeeper-dist/src/main/resources/NOTICE-all.bin.txt

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -93,13 +93,13 @@ SoundCloud Ltd. (http://soundcloud.com/).
9393
This product includes software developed as part of the
9494
Ocelli project by Netflix Inc. (https://github.com/Netflix/ocelli/).
9595
------------------------------------------------------------------------------------
96-
- lib/org.eclipse.jetty-jetty-http-9.4.53.v20231009.jar
97-
- lib/org.eclipse.jetty-jetty-io-9.4.53.v20231009.jar
98-
- lib/org.eclipse.jetty-jetty-security-9.4.53.v20231009.jar
99-
- lib/org.eclipse.jetty-jetty-server-9.4.53.v20231009.jar
100-
- lib/org.eclipse.jetty-jetty-servlet-9.4.53.v20231009.jar
101-
- lib/org.eclipse.jetty-jetty-util-9.4.53.v20231009.jar
102-
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.53.v20231009.jar
96+
- lib/org.eclipse.jetty-jetty-http-9.4.57.v20241219.jar
97+
- lib/org.eclipse.jetty-jetty-io-9.4.57.v20241219.jar
98+
- lib/org.eclipse.jetty-jetty-security-9.4.57.v20241219.jar
99+
- lib/org.eclipse.jetty-jetty-server-9.4.57.v20241219.jar
100+
- lib/org.eclipse.jetty-jetty-servlet-9.4.57.v20241219.jar
101+
- lib/org.eclipse.jetty-jetty-util-9.4.57.v20241219.jar
102+
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.57.v20241219.jar
103103

104104
==============================================================
105105
Jetty Web Container
@@ -121,7 +121,7 @@ Jetty is dual licensed under both
121121

122122
Jetty may be distributed under either license.
123123

124-
lib/org.eclipse.jetty-jetty-util-9.4.53.v20231009.jar bundles UnixCrypt
124+
lib/org.eclipse.jetty-jetty-util-9.4.57.v20241219.jar bundles UnixCrypt
125125

126126
The UnixCrypt.java code implements the one way cryptography used by
127127
Unix systems for simple password protection. Copyright 1996 Aki Yoshida,

bookkeeper-dist/src/main/resources/NOTICE-server.bin.txt

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -75,13 +75,13 @@ SoundCloud Ltd. (http://soundcloud.com/).
7575
This product includes software developed as part of the
7676
Ocelli project by Netflix Inc. (https://github.com/Netflix/ocelli/).
7777
------------------------------------------------------------------------------------
78-
- lib/org.eclipse.jetty-jetty-http-9.4.53.v20231009.jar
79-
- lib/org.eclipse.jetty-jetty-io-9.4.53.v20231009.jar
80-
- lib/org.eclipse.jetty-jetty-security-9.4.53.v20231009.jar
81-
- lib/org.eclipse.jetty-jetty-server-9.4.53.v20231009.jar
82-
- lib/org.eclipse.jetty-jetty-servlet-9.4.53.v20231009.jar
83-
- lib/org.eclipse.jetty-jetty-util-9.4.53.v20231009.jar
84-
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.53.v20231009.jar
78+
- lib/org.eclipse.jetty-jetty-http-9.4.57.v20241219.jar
79+
- lib/org.eclipse.jetty-jetty-io-9.4.57.v20241219.jar
80+
- lib/org.eclipse.jetty-jetty-security-9.4.57.v20241219.jar
81+
- lib/org.eclipse.jetty-jetty-server-9.4.57.v20241219.jar
82+
- lib/org.eclipse.jetty-jetty-servlet-9.4.57.v20241219.jar
83+
- lib/org.eclipse.jetty-jetty-util-9.4.57.v20241219.jar
84+
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.57.v20241219.jar
8585

8686
==============================================================
8787
Jetty Web Container
@@ -103,7 +103,7 @@ Jetty is dual licensed under both
103103

104104
Jetty may be distributed under either license.
105105

106-
lib/org.eclipse.jetty-jetty-util-9.4.53.v20231009.jar bundles UnixCrypt
106+
lib/org.eclipse.jetty-jetty-util-9.4.57.v20241219.jar bundles UnixCrypt
107107

108108
The UnixCrypt.java code implements the one way cryptography used by
109109
Unix systems for simple password protection. Copyright 1996 Aki Yoshida,

pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -142,7 +142,7 @@
142142
<hdrhistogram.version>2.1.10</hdrhistogram.version>
143143
<jackson.version>2.17.1</jackson.version>
144144
<jcommander.version>1.82</jcommander.version>
145-
<jetty.version>9.4.53.v20231009</jetty.version>
145+
<jetty.version>9.4.57.v20241219</jetty.version>
146146
<jmh.version>1.37</jmh.version>
147147
<jmock.version>2.8.2</jmock.version>
148148
<jsoup.version>1.15.3</jsoup.version>

0 commit comments

Comments
 (0)