Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

KC-1456: Update jetty to 9.4.35.v2020112 #526

Conversation

omkreddy
Copy link
Member

@omkreddy omkreddy commented Feb 22, 2021

Update jetty to fix https://nvd.nist.gov/vuln/detail/CVE-2020-27218
https://github.com/eclipse/jetty.project/releases/tag/jetty-9.4.35.v20201120

This can be backported up to 2.4 releases which are using recent version 9.4.33.v20201020. This can be risky update for 2.3 and earlier releases. We also need to update common module. Ran Kafka System tests and Platform system tests and results look good.

Committer Checklist (excluded from commit message)

  • Verify design and implementation
  • Verify test coverage and CI build status
  • Verify documentation (including upgrade notes)

Copy link
Member

@ijuma ijuma left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks.

@omkreddy
Copy link
Member Author

Jetty merged in AK branches, closing this.

@omkreddy omkreddy closed this Feb 22, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants