Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[fix][security] Upgrade to Jetty to 9.4.48.v20220622 to get rid of CVE-2022-2047 #16520

Merged
merged 3 commits into from Jul 12, 2022

Conversation

nicoloboschi
Copy link
Contributor

Motivation

Owasp check fails because jetty 9.4.44 is marked as vulnerable due to CVE-2022-2047

Note that Jetty 9.4.x is EOL after 9.4.48.v20220622

Modifications

  • doc-not-needed

@github-actions github-actions bot added the doc-not-needed Your PR changes do not impact docs label Jul 11, 2022
@nicoloboschi
Copy link
Contributor Author

/pulsarbot rerun-failure-checks

@merlimat merlimat merged commit 6872ac3 into apache:master Jul 12, 2022
nicoloboschi added a commit that referenced this pull request Jul 13, 2022
…E-2022-2047 (#16520)

* [fix][security] Upgrade to Jetty to 9.4.48.v20220622 to get rid of CVE-2022-2047

* suppress CVE-2022-2191 - false positive

* Revert "suppress CVE-2022-2191 - false positive"

This reverts commit ab4601f.

(cherry picked from commit 6872ac3)
nicoloboschi added a commit that referenced this pull request Jul 13, 2022
…E-2022-2047 (#16520)

* [fix][security] Upgrade to Jetty to 9.4.48.v20220622 to get rid of CVE-2022-2047

* suppress CVE-2022-2191 - false positive

* Revert "suppress CVE-2022-2191 - false positive"

This reverts commit ab4601f.

(cherry picked from commit 6872ac3)
nicoloboschi added a commit that referenced this pull request Jul 13, 2022
…E-2022-2047 (#16520)

* [fix][security] Upgrade to Jetty to 9.4.48.v20220622 to get rid of CVE-2022-2047

* suppress CVE-2022-2191 - false positive

* Revert "suppress CVE-2022-2191 - false positive"

This reverts commit ab4601f.

(cherry picked from commit 6872ac3)
(cherry picked from commit 87f64d0)
@nicoloboschi nicoloboschi added cherry-picked/branch-2.8 Archived: 2.8 is end of life cherry-picked/branch-2.9 Archived: 2.9 is end of life cherry-picked/branch-2.10 labels Jul 13, 2022
nicoloboschi added a commit to datastax/pulsar that referenced this pull request Jul 13, 2022
…E-2022-2047 (apache#16520)

* [fix][security] Upgrade to Jetty to 9.4.48.v20220622 to get rid of CVE-2022-2047

* suppress CVE-2022-2191 - false positive

* Revert "suppress CVE-2022-2191 - false positive"

This reverts commit ab4601f.

(cherry picked from commit 6872ac3)
(cherry picked from commit eb5e6af)
wuxuanqicn pushed a commit to wuxuanqicn/pulsar that referenced this pull request Jul 14, 2022
…E-2022-2047 (apache#16520)

* [fix][security] Upgrade to Jetty to 9.4.48.v20220622 to get rid of CVE-2022-2047

* suppress CVE-2022-2191 - false positive

* Revert "suppress CVE-2022-2191 - false positive"

This reverts commit ab4601f.
nicoloboschi added a commit to datastax/pulsar that referenced this pull request Jul 21, 2022
…E-2022-2047 (apache#16520)

* [fix][security] Upgrade to Jetty to 9.4.48.v20220622 to get rid of CVE-2022-2047

* suppress CVE-2022-2191 - false positive

* Revert "suppress CVE-2022-2191 - false positive"

This reverts commit ab4601f.

(cherry picked from commit 6872ac3)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/dependency Pull requests that update a dependency file cherry-picked/branch-2.8 Archived: 2.8 is end of life cherry-picked/branch-2.9 Archived: 2.9 is end of life cherry-picked/branch-2.10 doc-not-needed Your PR changes do not impact docs release/2.8.4 release/2.9.4 release/2.10.2
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

6 participants