-
Notifications
You must be signed in to change notification settings - Fork 6
Open
Description
Support for Jetty 12 with Jakarta EE 10 to address CVE-2024-6763
This is for series/0.24
Why?
- Jetty versions from
7.0.0up to12.0.11are affected by CVE-2024-6763 (Eclipse Jetty URI parsing of invalid authority). - The current version of
http4s-jettyuses Jetty10. - Community support for Jetty 10 and Jetty 11 ended in January 2024.
- To solve the issue,
http4s-jettyshould use Jetty12, the current stable version.
Any Other Things to Know?
- Jetty
12requires Java17, so dropping support for Java11is necessary. - Jetty has multiple versions supporting different versions of Jakarta EE (Java EE), and this ticket is only for Jakarta EE
10.
Additional Notes:
- Close #7578: http4s
0.22: Add support for Jetty12to addressCVE-2024-6763http4s#7579 - I’ve already been working on the JEE
8one and will do the same for JEE10.
Metadata
Metadata
Assignees
Labels
No labels