Skip to content

Upgrade Jetty to 9.4.57.v20241219 to mitigate CVE-2024-6763#4600

Merged
hezhangjian merged 1 commit intoapache:masterfrom
lhotari:lh-address-CVE-2024-6763
May 6, 2025
Merged

Upgrade Jetty to 9.4.57.v20241219 to mitigate CVE-2024-6763#4600
hezhangjian merged 1 commit intoapache:masterfrom
lhotari:lh-address-CVE-2024-6763

Conversation

@lhotari
Copy link
Member

@lhotari lhotari commented Apr 30, 2025

Motivation & Changes

Upgrade Jetty to 9.4.57.v20241219 to address CVE-2024-6763
Jetty 9.4.57.v20241219 contains backported CVE-2024-6763 fix in jetty/jetty.project#12532 although it's not explicitly mentioned and most security scanners don't yet contain the information that it's been addressed in 9.4.57.
More details:

Note: The backport is a partial mitigation and Jetty 9.4.57 will continue to be marked as vulnerable. There's a discussion and explanation here: https://gitlab.eclipse.org/security/cve-assignement/-/issues/25#note_2968611

@lhotari lhotari added this to the 4.18.0 milestone Apr 30, 2025
@lhotari lhotari self-assigned this Apr 30, 2025
@lhotari lhotari changed the title Upgrade Jetty to 9.4.57.v20241219 to address CVE-2024-6763 Upgrade Jetty to 9.4.57.v20241219 to mitigate CVE-2024-6763 Apr 30, 2025
@joakime
Copy link

joakime commented May 1, 2025

@lhotari
Copy link
Member Author

lhotari commented May 1, 2025

Jetty 9 is EOL and should not be used.

@joakime Yes, we are aware of that. There's work in progress to upgrade to Jetty 12.

@joakime
Copy link

joakime commented May 1, 2025

@joakime Yes, we are aware of that. There's work in progress to upgrade to Jetty 12.

Feel free to reach out to us for any help you need.

Copy link
Member

@StevenLuMT StevenLuMT left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good jobs

@StevenLuMT
Copy link
Member

rerun failure checks

@hezhangjian hezhangjian merged commit 99eb63a into apache:master May 6, 2025
23 checks passed
StevenLuMT pushed a commit that referenced this pull request Jun 12, 2025
### Motivation & Changes

Upgrade Jetty to 9.4.57.v20241219 to address CVE-2024-6763
Jetty 9.4.57.v20241219 contains backported CVE-2024-6763 fix in jetty/jetty.project#12532 although it's not explicitly mentioned and most security scanners don't yet contain the information that it's been addressed in 9.4.57.
More details:
* jetty/jetty.project#12630
* https://github.com/jetty/jetty.project/releases/tag/jetty-9.4.57.v20241219

Note: The backport is a partial mitigation and Jetty 9.4.57 will continue to be marked as vulnerable. There's a discussion and explanation here: https://gitlab.eclipse.org/security/cve-assignement/-/issues/25#note_2968611

(cherry picked from commit 99eb63a)
StevenLuMT pushed a commit that referenced this pull request Jun 12, 2025
### Motivation & Changes

Upgrade Jetty to 9.4.57.v20241219 to address CVE-2024-6763
Jetty 9.4.57.v20241219 contains backported CVE-2024-6763 fix in jetty/jetty.project#12532 although it's not explicitly mentioned and most security scanners don't yet contain the information that it's been addressed in 9.4.57.
More details:
* jetty/jetty.project#12630
* https://github.com/jetty/jetty.project/releases/tag/jetty-9.4.57.v20241219

Note: The backport is a partial mitigation and Jetty 9.4.57 will continue to be marked as vulnerable. There's a discussion and explanation here: https://gitlab.eclipse.org/security/cve-assignement/-/issues/25#note_2968611

(cherry picked from commit 99eb63a)
StevenLuMT added a commit to StevenLuMT/bookkeeper that referenced this pull request Jul 6, 2025
StevenLuMT added a commit to StevenLuMT/bookkeeper that referenced this pull request Jul 6, 2025
StevenLuMT added a commit to StevenLuMT/bookkeeper that referenced this pull request Jul 6, 2025
StevenLuMT added a commit to StevenLuMT/bookkeeper that referenced this pull request Jul 6, 2025
priyanshu-ctds pushed a commit to datastax/bookkeeper that referenced this pull request Jul 11, 2025
### Motivation & Changes

Upgrade Jetty to 9.4.57.v20241219 to address CVE-2024-6763
Jetty 9.4.57.v20241219 contains backported CVE-2024-6763 fix in jetty/jetty.project#12532 although it's not explicitly mentioned and most security scanners don't yet contain the information that it's been addressed in 9.4.57.
More details:
* jetty/jetty.project#12630
* https://github.com/jetty/jetty.project/releases/tag/jetty-9.4.57.v20241219

Note: The backport is a partial mitigation and Jetty 9.4.57 will continue to be marked as vulnerable. There's a discussion and explanation here: https://gitlab.eclipse.org/security/cve-assignement/-/issues/25#note_2968611

(cherry picked from commit 99eb63a)
(cherry picked from commit 7c58be4)
priyanshu-ctds pushed a commit to datastax/bookkeeper that referenced this pull request Jul 11, 2025
sandeep-ctds pushed a commit to datastax/bookkeeper that referenced this pull request Jul 22, 2025
### Motivation & Changes

Upgrade Jetty to 9.4.57.v20241219 to address CVE-2024-6763
Jetty 9.4.57.v20241219 contains backported CVE-2024-6763 fix in jetty/jetty.project#12532 although it's not explicitly mentioned and most security scanners don't yet contain the information that it's been addressed in 9.4.57.
More details:
* jetty/jetty.project#12630
* https://github.com/jetty/jetty.project/releases/tag/jetty-9.4.57.v20241219

Note: The backport is a partial mitigation and Jetty 9.4.57 will continue to be marked as vulnerable. There's a discussion and explanation here: https://gitlab.eclipse.org/security/cve-assignement/-/issues/25#note_2968611

(cherry picked from commit 99eb63a)
(cherry picked from commit 7c58be4)
sandeep-ctds pushed a commit to datastax/bookkeeper that referenced this pull request Jul 22, 2025
manas-ctds pushed a commit to datastax/bookkeeper that referenced this pull request Feb 27, 2026
### Motivation & Changes

Upgrade Jetty to 9.4.57.v20241219 to address CVE-2024-6763
Jetty 9.4.57.v20241219 contains backported CVE-2024-6763 fix in jetty/jetty.project#12532 although it's not explicitly mentioned and most security scanners don't yet contain the information that it's been addressed in 9.4.57.
More details:
* jetty/jetty.project#12630
* https://github.com/jetty/jetty.project/releases/tag/jetty-9.4.57.v20241219

Note: The backport is a partial mitigation and Jetty 9.4.57 will continue to be marked as vulnerable. There's a discussion and explanation here: https://gitlab.eclipse.org/security/cve-assignement/-/issues/25#note_2968611

(cherry picked from commit 99eb63a)
(cherry picked from commit cda3c6b)
manas-ctds pushed a commit to datastax/bookkeeper that referenced this pull request Feb 27, 2026
dlg99 pushed a commit to datastax/bookkeeper that referenced this pull request Feb 27, 2026
### Motivation & Changes

Upgrade Jetty to 9.4.57.v20241219 to address CVE-2024-6763
Jetty 9.4.57.v20241219 contains backported CVE-2024-6763 fix in jetty/jetty.project#12532 although it's not explicitly mentioned and most security scanners don't yet contain the information that it's been addressed in 9.4.57.
More details:
* jetty/jetty.project#12630
* https://github.com/jetty/jetty.project/releases/tag/jetty-9.4.57.v20241219

Note: The backport is a partial mitigation and Jetty 9.4.57 will continue to be marked as vulnerable. There's a discussion and explanation here: https://gitlab.eclipse.org/security/cve-assignement/-/issues/25#note_2968611

(cherry picked from commit 99eb63a)
(cherry picked from commit cda3c6b)
dlg99 pushed a commit to datastax/bookkeeper that referenced this pull request Feb 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants