SEZ9 commented on issue #12002:
URL: https://github.com/apache/seatunnel/issues/12002#issuecomment-5476213837

   Thanks for the follow-up, @davidzollo. Agreed — a PR is the right next step 
here.
   
   To recap the scope from the earlier review, the PR should cover two things:
   
   1. **Upgrade the embedded Jetty from 9.4.56** to a version that addresses 
CVE-2025-5115 and CVE-2024-6763.
   2. **Disable the `Server` version header disclosure** in Zeta's 
JettyService, so the Jetty version is not exposed in HTTP responses.
   
   A couple of concrete asks for whoever picks this up:
   
   - Please keep both changes in the same PR (or clearly linked PRs) so the CVE 
remediation and the header hardening can be verified together.
   - In the PR description, note the exact Jetty version chosen and confirm it 
resolves both CVEs listed above.
   - Include a quick verification (e.g., a response header check) showing the 
`Server` header no longer leaks the version after the change.
   
   Happy to review once the PR is up. Thanks!
   
   <!-- streview-comment:701 -->


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to