[ 
https://issues.apache.org/jira/browse/CXF-9068?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17890049#comment-17890049
 ] 

Andriy Redko commented on CXF-9068:
-----------------------------------

The upcoming 4.0.6 have Jetty updated. For 4.0.5, please use dependency 
overrides (depending which build tool you are using) to bundle more recent 
Jetty version along with your application(s). Thanks.

> Vulnerability (Denial of Service) in jetty server
> -------------------------------------------------
>
>                 Key: CXF-9068
>                 URL: https://issues.apache.org/jira/browse/CXF-9068
>             Project: CXF
>          Issue Type: Bug
>          Components: Transports
>    Affects Versions: 4.0.5
>            Reporter: Milan Siebenbürger
>            Priority: Major
>
> Hello,
>  
> snyk.io has discovered a vulnerability in Jetty Server 
> ([https://security.snyk.io/vuln/SNYK-JAVA-ORGECLIPSEJETTY-8186142] ), which 
> was introduced via org.apache.cxf:[email protected] 
>  
> Is it possible to fix or mitigate this issue?
> thanks
> Milan Siebenbürger



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to