Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Jetty libraries to 9.4.39.v20210325 #10177

Merged
merged 1 commit into from
Apr 10, 2021

Conversation

massakam
Copy link
Contributor

@massakam massakam commented Apr 9, 2021

The version of Jetty currently used by Pulsar has the following vulnerability:
https://nvd.nist.gov/vuln/detail/CVE-2021-28165
This issue has been fixed in version 9.4.39.v20210325, so upgraded Jetty to that version.

@massakam massakam added this to the 2.8.0 milestone Apr 9, 2021
@massakam massakam self-assigned this Apr 9, 2021
Copy link
Contributor

@eolivelli eolivelli left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@lhotari PTAL

Copy link
Member

@lhotari lhotari left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@merlimat merlimat mentioned this pull request Apr 10, 2021
1 task
@merlimat merlimat merged commit 56bad04 into apache:master Apr 10, 2021
@massakam massakam deleted the upgrade-jetty branch April 12, 2021 02:38
zymap pushed a commit that referenced this pull request Apr 14, 2021
@zymap zymap added the cherry-picked/branch-2.7 Archived: 2.7 is end of life label Apr 14, 2021
lhotari added a commit to lhotari/pulsar that referenced this pull request Jun 11, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

6 participants