[ https://issues.apache.org/jira/browse/HADOOP-19225?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18010440#comment-18010440 ]
Jose Angel Riarola commented on HADOOP-19225: --------------------------------------------- Reporting that we have successfully tested this in our environments and this collection of CVEs seem resolved in the current rc of 3.4.2. > Upgrade Jetty to 9.4.57.v20241219 due to CVE-2024-8184 and other CVEs > --------------------------------------------------------------------- > > Key: HADOOP-19225 > URL: https://issues.apache.org/jira/browse/HADOOP-19225 > Project: Hadoop Common > Issue Type: Improvement > Components: build > Reporter: Palakur Eshwitha Sai > Assignee: PJ Fanning > Priority: Major > Labels: pull-request-available > Fix For: 3.5.0, 3.4.2 > > > Upgrade to jetty 9.4.56 due to > [CVE-2024-22201|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22201] > [CVE-2023-44487|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-44487] > [CVE-2024-8184|https://nvd.nist.gov/vuln/detail/CVE-2024-8184] : > [https://github.com/advisories/GHSA-g8m5-722r-8whq] > [CVE-2024-13009|https://nvd.nist.gov/vuln/detail/CVE-2024-13009] -- This message was sent by Atlassian Jira (v8.20.10#820010) --------------------------------------------------------------------- To unsubscribe, e-mail: common-issues-unsubscr...@hadoop.apache.org For additional commands, e-mail: common-issues-h...@hadoop.apache.org