[
https://issues.apache.org/jira/browse/ATLAS-4923?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17899072#comment-17899072
]
Chenglong Hu commented on ATLAS-4923:
-------------------------------------
[~madhan] do we have any plan to upgrade jetty to 12.0.12 according to this
vulnerability?
[Eclipse Jetty URI parsing of invalid authority · CVE-2024-6763 · GitHub
Advisory Database|https://github.com/advisories/GHSA-qh8g-58pp-2wxh]
> Bump dependent component versions (dependabot) for commons-fileupload, testng
> -----------------------------------------------------------------------------
>
> Key: ATLAS-4923
> URL: https://issues.apache.org/jira/browse/ATLAS-4923
> Project: Atlas
> Issue Type: Improvement
> Components: atlas-core
> Reporter: Madhan Neethiraj
> Assignee: Madhan Neethiraj
> Priority: Major
> Fix For: 3.0.0
>
> Attachments: ATLAS-4923-2.patch
>
>
> Update version of following dependent components as suggested by dependabot:
> * commons-fileupload [https://github.com/apache/atlas/pull/227]
> * testng [https://github.com/apache/atlas/pull/230]
> In addition, jetty version is updated from 9.4.53.v20231009 to
> 9.4.56.v20240826.
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)