Re: Jetty(Jetty 9.4.52) vulnerability in Karaf 4.3.10

2024-03-03 Thread Jean-Baptiste Onofré
In that case, please double check first if you are actually impacted by the CVE. It's possible to tweak your karaf version by updating, but you have to do it "cold". Regards JB On Mon, Mar 4, 2024 at 6:21 AM Chandan Singh wrote: > > Hi JB , > > Can you please share how to upgrade just

Re: Jetty(Jetty 9.4.52) vulnerability in Karaf 4.3.10

2024-03-03 Thread Grzegorz Grzybek
Hello If you're already in production, I'd think twice before upgrading to Pax Web 8 - it changes A LOT. You _may_ be dependent on some not-spec-compliant behavior of Pax Web 7 used in Karaf 4.3. Also (though I'm not a security expert, so I can't take responsibility if you in any way use my

Re: Jetty(Jetty 9.4.52) vulnerability in Karaf 4.3.10

2024-03-03 Thread Chandan Singh
Hi JB , Can you please share how to upgrade just PAxweb/Jetty in the 4.3.10 version? We are already in prod and I cannot upgrade to a new Karaf version . Regards Chandan On Fri, Mar 1, 2024 at 12:41 PM Jean-Baptiste Onofré wrote: > Hi > > You can create your own custom Karaf distribution