-
Notifications
You must be signed in to change notification settings - Fork 9.1k
HADOOP-19225. Upgrade Jetty to 9.4.57.v20241219 due to CVE-2024-8184 #7116
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
💔 -1 overall
This message was automatically generated. |
a86117d
to
35f2b84
Compare
rebased |
Please update the subject and include "Jetty" in it. |
💔 -1 overall
This message was automatically generated. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
The JDK-11 failure is known & being tracked separately
35f2b84
to
07781a1
Compare
💔 -1 overall
This message was automatically generated. |
@slfan1989 @ayushtkn @steveloughran would it be possible to merge this (if it is ok)? |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think we have 9.4.57.v20241219 as well released now, can we move to it directly?
07781a1
to
643ab22
Compare
💔 -1 overall
This message was automatically generated. |
upgraded to 9.4.57 |
…pache#7116). Contributed by PJ Fanning.
…pache#7116). Contributed by PJ Fanning.
…pache#7116). Contributed by PJ Fanning.
Description of PR
CVE-2024-8184 - Might as well use latest Jetty release 9.4.57.v20241219 because this release line is EOL and only serious bugs are fixed in it
HADOOP-19225
How was this patch tested?
For code changes:
LICENSE
,LICENSE-binary
,NOTICE-binary
files?