This is an automated email from the ASF dual-hosted git repository.
manikumar pushed a commit to branch 2.8
in repository https://gitbox.apache.org/repos/asf/kafka.git
The following commit(s) were added to refs/heads/2.8 by this push:
new 8ed0c22 KAFKA-12400: Upgrade jetty to fix CVE-2020-27223
8ed0c22 is described below
commit 8ed0c2289692a3b31427e8619a7e363f539696c4
Author: Lee Dongjin <[email protected]>
AuthorDate: Wed Mar 3 10:13:40 2021 +0530
KAFKA-12400: Upgrade jetty to fix CVE-2020-27223
Here is the fix. The reason of
[CVE-2020-27223](https://nvd.nist.gov/vuln/detail/CVE-2020-27223) was DOS
vulnerability for Quoted Quality CSV headers and [patched in
9.4.37.v20210219](https://github.com/eclipse/jetty.project/security/advisories/GHSA-m394-8rww-3jr7).
This PR updates Jetty dependency into the following version,
9.4.38.v20210224.
Author: Lee Dongjin <[email protected]>
Reviewers: Manikumar Reddy <[email protected]>
Closes #10245 from dongjinleekr/feature/KAFKA-12400
(cherry picked from commit b77deece1db3fca5575e336e157677f83bf3b506)
Signed-off-by: Manikumar Reddy <[email protected]>
---
gradle/dependencies.gradle | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/gradle/dependencies.gradle b/gradle/dependencies.gradle
index 512ffbe..6b09595 100644
--- a/gradle/dependencies.gradle
+++ b/gradle/dependencies.gradle
@@ -70,7 +70,7 @@ versions += [
jacksonDatabind: "2.10.5.1",
jacoco: "0.8.5",
javassist: "3.27.0-GA",
- jetty: "9.4.36.v20210114",
+ jetty: "9.4.38.v20210224",
jersey: "2.31",
jline: "3.12.1",
jmh: "1.27",