SEZ9 commented on issue #12002: URL: https://github.com/apache/seatunnel/issues/12002#issuecomment-5476213837
Thanks for the follow-up, @davidzollo. Agreed — a PR is the right next step here. To recap the scope from the earlier review, the PR should cover two things: 1. **Upgrade the embedded Jetty from 9.4.56** to a version that addresses CVE-2025-5115 and CVE-2024-6763. 2. **Disable the `Server` version header disclosure** in Zeta's JettyService, so the Jetty version is not exposed in HTTP responses. A couple of concrete asks for whoever picks this up: - Please keep both changes in the same PR (or clearly linked PRs) so the CVE remediation and the header hardening can be verified together. - In the PR description, note the exact Jetty version chosen and confirm it resolves both CVEs listed above. - Include a quick verification (e.g., a response header check) showing the `Server` header no longer leaks the version after the change. Happy to review once the PR is up. Thanks! <!-- streview-comment:701 --> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
