Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to Jetty 12 for CVE-2024-6763 #17492

Closed
ashibhardwaj opened this issue Nov 20, 2024 · 1 comment
Closed

Upgrade to Jetty 12 for CVE-2024-6763 #17492

ashibhardwaj opened this issue Nov 20, 2024 · 1 comment

Comments

@ashibhardwaj
Copy link
Contributor

CVE-2024-6763 requires upgrade to jetty version 12.0.12 or above. This will require significant changes as the current jetty version being used is 9.4.56.v20240826.

Relevant links:

@ashibhardwaj
Copy link
Contributor Author

Closing this issue as the CVE only impacts direct usage of HttpURI class which is not the case in Druid and hence should not be vulnerable.
However, Jetty 9 is EOL and we should plan upgrading to Jetty 12.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant