[ 
https://issues.apache.org/jira/browse/KARAF-7692?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Karthick updated KARAF-7692:
----------------------------
    Description: As per CVE [https://nvd.nist.gov/vuln/detail/CVE-2023-26048] , 
Jetty version till 9.4.50 is impacted in a multipart issue. This is howwver 
fixed by jetty in later versions. We use Apache Karaf that brings the Jetty 
through pax-web. Please stepup the components so that the final karaf runtime 
has 9.4.51 Jetty in it.  (was: The latest version of Apache Karaf 4.3.8 and 
4.4.2 uses Apache MINA SSHD 2.9.1 which is impacted by critical vulnerability 
cve-2022-45047.

 

Please stepup this library to > 2.9.1 to solve this.)

> Upgrade Jetty to 9.4.51
> -----------------------
>
>                 Key: KARAF-7692
>                 URL: https://issues.apache.org/jira/browse/KARAF-7692
>             Project: Karaf
>          Issue Type: Dependency upgrade
>          Components: karaf
>    Affects Versions: 4.4.3, 4.3.9
>            Reporter: Karthick
>            Assignee: Jean-Baptiste Onofré
>            Priority: Major
>              Labels: dependency-upgrade
>
> As per CVE [https://nvd.nist.gov/vuln/detail/CVE-2023-26048] , Jetty version 
> till 9.4.50 is impacted in a multipart issue. This is howwver fixed by jetty 
> in later versions. We use Apache Karaf that brings the Jetty through pax-web. 
> Please stepup the components so that the final karaf runtime has 9.4.51 Jetty 
> in it.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to