Skip to content

Commit

Permalink
[fix][security] Upgrade to Jetty to 9.4.48.v20220622 to get rid of CV…
Browse files Browse the repository at this point in the history
…E-2022-2047 (#16520)

* [fix][security] Upgrade to Jetty to 9.4.48.v20220622 to get rid of CVE-2022-2047

* suppress CVE-2022-2191 - false positive

* Revert "suppress CVE-2022-2191 - false positive"

This reverts commit ab4601f.
  • Loading branch information
nicoloboschi committed Jul 12, 2022
1 parent de343c8 commit 6872ac3
Show file tree
Hide file tree
Showing 3 changed files with 36 additions and 36 deletions.
38 changes: 19 additions & 19 deletions distribution/server/src/assemble/LICENSE.bin.txt
Expand Up @@ -429,25 +429,25 @@ The Apache Software License, Version 2.0
- org.asynchttpclient-async-http-client-2.12.1.jar
- org.asynchttpclient-async-http-client-netty-utils-2.12.1.jar
* Jetty
- org.eclipse.jetty-jetty-client-9.4.44.v20210927.jar
- org.eclipse.jetty-jetty-continuation-9.4.44.v20210927.jar
- org.eclipse.jetty-jetty-http-9.4.44.v20210927.jar
- org.eclipse.jetty-jetty-io-9.4.44.v20210927.jar
- org.eclipse.jetty-jetty-proxy-9.4.44.v20210927.jar
- org.eclipse.jetty-jetty-security-9.4.44.v20210927.jar
- org.eclipse.jetty-jetty-server-9.4.44.v20210927.jar
- org.eclipse.jetty-jetty-servlet-9.4.44.v20210927.jar
- org.eclipse.jetty-jetty-servlets-9.4.44.v20210927.jar
- org.eclipse.jetty-jetty-util-9.4.44.v20210927.jar
- org.eclipse.jetty-jetty-util-ajax-9.4.44.v20210927.jar
- org.eclipse.jetty.websocket-javax-websocket-client-impl-9.4.44.v20210927.jar
- org.eclipse.jetty.websocket-websocket-api-9.4.44.v20210927.jar
- org.eclipse.jetty.websocket-websocket-client-9.4.44.v20210927.jar
- org.eclipse.jetty.websocket-websocket-common-9.4.44.v20210927.jar
- org.eclipse.jetty.websocket-websocket-server-9.4.44.v20210927.jar
- org.eclipse.jetty.websocket-websocket-servlet-9.4.44.v20210927.jar
- org.eclipse.jetty-jetty-alpn-conscrypt-server-9.4.44.v20210927.jar
- org.eclipse.jetty-jetty-alpn-server-9.4.44.v20210927.jar
- org.eclipse.jetty-jetty-client-9.4.48.v20220622.jar
- org.eclipse.jetty-jetty-continuation-9.4.48.v20220622.jar
- org.eclipse.jetty-jetty-http-9.4.48.v20220622.jar
- org.eclipse.jetty-jetty-io-9.4.48.v20220622.jar
- org.eclipse.jetty-jetty-proxy-9.4.48.v20220622.jar
- org.eclipse.jetty-jetty-security-9.4.48.v20220622.jar
- org.eclipse.jetty-jetty-server-9.4.48.v20220622.jar
- org.eclipse.jetty-jetty-servlet-9.4.48.v20220622.jar
- org.eclipse.jetty-jetty-servlets-9.4.48.v20220622.jar
- org.eclipse.jetty-jetty-util-9.4.48.v20220622.jar
- org.eclipse.jetty-jetty-util-ajax-9.4.48.v20220622.jar
- org.eclipse.jetty.websocket-javax-websocket-client-impl-9.4.48.v20220622.jar
- org.eclipse.jetty.websocket-websocket-api-9.4.48.v20220622.jar
- org.eclipse.jetty.websocket-websocket-client-9.4.48.v20220622.jar
- org.eclipse.jetty.websocket-websocket-common-9.4.48.v20220622.jar
- org.eclipse.jetty.websocket-websocket-server-9.4.48.v20220622.jar
- org.eclipse.jetty.websocket-websocket-servlet-9.4.48.v20220622.jar
- org.eclipse.jetty-jetty-alpn-conscrypt-server-9.4.48.v20220622.jar
- org.eclipse.jetty-jetty-alpn-server-9.4.48.v20220622.jar
* SnakeYaml -- org.yaml-snakeyaml-1.30.jar
* RocksDB - org.rocksdb-rocksdbjni-6.29.4.1.jar
* Google Error Prone Annotations - com.google.errorprone-error_prone_annotations-2.5.1.jar
Expand Down
2 changes: 1 addition & 1 deletion pom.xml
Expand Up @@ -122,7 +122,7 @@ flexible messaging model and an intuitive client API.</description>
<curator.version>5.1.0</curator.version>
<netty.version>4.1.77.Final</netty.version>
<netty-tc-native.version>2.0.52.Final</netty-tc-native.version>
<jetty.version>9.4.44.v20210927</jetty.version>
<jetty.version>9.4.48.v20220622</jetty.version>
<conscrypt.version>2.5.2</conscrypt.version>
<jersey.version>2.34</jersey.version>
<athenz.version>1.10.50</athenz.version>
Expand Down
32 changes: 16 additions & 16 deletions pulsar-sql/presto-distribution/LICENSE
Expand Up @@ -274,22 +274,22 @@ The Apache Software License, Version 2.0
- joda-time-2.10.5.jar
- failsafe-2.4.4.jar
* Jetty
- http2-client-9.4.44.v20210927.jar
- http2-common-9.4.44.v20210927.jar
- http2-hpack-9.4.44.v20210927.jar
- http2-http-client-transport-9.4.44.v20210927.jar
- jetty-alpn-client-9.4.44.v20210927.jar
- http2-server-9.4.44.v20210927.jar
- jetty-alpn-java-client-9.4.44.v20210927.jar
- jetty-client-9.4.44.v20210927.jar
- jetty-http-9.4.44.v20210927.jar
- jetty-io-9.4.44.v20210927.jar
- jetty-jmx-9.4.44.v20210927.jar
- jetty-security-9.4.44.v20210927.jar
- jetty-server-9.4.44.v20210927.jar
- jetty-servlet-9.4.44.v20210927.jar
- jetty-util-9.4.44.v20210927.jar
- jetty-util-ajax-9.4.44.v20210927.jar
- http2-client-9.4.48.v20220622.jar
- http2-common-9.4.48.v20220622.jar
- http2-hpack-9.4.48.v20220622.jar
- http2-http-client-transport-9.4.48.v20220622.jar
- jetty-alpn-client-9.4.48.v20220622.jar
- http2-server-9.4.48.v20220622.jar
- jetty-alpn-java-client-9.4.48.v20220622.jar
- jetty-client-9.4.48.v20220622.jar
- jetty-http-9.4.48.v20220622.jar
- jetty-io-9.4.48.v20220622.jar
- jetty-jmx-9.4.48.v20220622.jar
- jetty-security-9.4.48.v20220622.jar
- jetty-server-9.4.48.v20220622.jar
- jetty-servlet-9.4.48.v20220622.jar
- jetty-util-9.4.48.v20220622.jar
- jetty-util-ajax-9.4.48.v20220622.jar
* Apache BVal
- bval-jsr-2.0.0.jar
* Bytecode
Expand Down

0 comments on commit 6872ac3

Please sign in to comment.