[
https://issues.apache.org/jira/browse/KARAF-7692?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Karthick updated KARAF-7692:
----------------------------
Description:
As per CVE [https://nvd.nist.gov/vuln/detail/CVE-2023-26048] , Jetty version
till 9.4.50 is impacted in a multipart issue. This is howwver fixed by jetty in
later versions. We use Apache Karaf that brings the Jetty through pax-web.
Please stepup the components so that the final karaf runtime has 9.4.51 Jetty
in it.
Other CVE [https://nvd.nist.gov/vuln/detail/CVE-2023-26049] is also fixed by
this stepup
was:
As per CVE [https://nvd.nist.gov/vuln/detail/CVE-2023-26048] , Jetty version
till 9.4.50 is impacted in a multipart issue. This is howwver fixed by jetty in
later versions. We use Apache Karaf that brings the Jetty through pax-web.
Please stepup the components so that the final karaf runtime has 9.4.51 Jetty
in it.
Other CVEs [https://nvd.nist.gov/vuln/detail/CVE-2023-26049] ,
[https://nvd.nist.gov/vuln/detail/CVE-2023-26048] are also fixed by this stepup
> Upgrade Jetty to 9.4.51
> -----------------------
>
> Key: KARAF-7692
> URL: https://issues.apache.org/jira/browse/KARAF-7692
> Project: Karaf
> Issue Type: Dependency upgrade
> Components: karaf
> Affects Versions: 4.4.3, 4.3.9
> Reporter: Karthick
> Assignee: Jean-Baptiste Onofré
> Priority: Major
> Labels: dependency-upgrade
>
> As per CVE [https://nvd.nist.gov/vuln/detail/CVE-2023-26048] , Jetty version
> till 9.4.50 is impacted in a multipart issue. This is howwver fixed by jetty
> in later versions. We use Apache Karaf that brings the Jetty through pax-web.
> Please stepup the components so that the final karaf runtime has 9.4.51 Jetty
> in it.
>
> Other CVE [https://nvd.nist.gov/vuln/detail/CVE-2023-26049] is also fixed by
> this stepup
--
This message was sent by Atlassian Jira
(v8.20.10#820010)