[ 
https://issues.apache.org/jira/browse/KARAF-7692?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17761227#comment-17761227
 ] 

ASF subversion and git services commented on KARAF-7692:
--------------------------------------------------------

Commit bcc0c9f40f4adf323fc0775bfe70b3fedafc7f1c in karaf's branch 
refs/heads/main from Robert Varga
[ https://gitbox.apache.org/repos/asf?p=karaf.git;h=bcc0c9f40f ]

[KARAF-7692]: Use pax-web-8.0.21

https://github.com/ops4j/org.ops4j.pax.web/milestone/238?closed=1
https://github.com/ops4j/org.ops4j.pax.web/milestone/239?closed=1
https://github.com/ops4j/org.ops4j.pax.web/milestone/241?closed=1
https://github.com/ops4j/org.ops4j.pax.web/milestone/243?closed=1
https://github.com/ops4j/org.ops4j.pax.web/milestone/245?closed=1
https://github.com/ops4j/org.ops4j.pax.web/milestone/247?closed=1

Also pick up Jetty 9.4.52.v20230823.

Signed-off-by: Robert Varga <[email protected]>


> Upgrade Pax Web 8.0.21 / Jetty to 9.4.52
> ----------------------------------------
>
>                 Key: KARAF-7692
>                 URL: https://issues.apache.org/jira/browse/KARAF-7692
>             Project: Karaf
>          Issue Type: Dependency upgrade
>          Components: karaf
>    Affects Versions: 4.4.3, 4.3.9
>            Reporter: Karthick
>            Assignee: Jean-Baptiste Onofré
>            Priority: Major
>              Labels: dependency-upgrade
>
> As per CVE [https://nvd.nist.gov/vuln/detail/CVE-2023-26048] , Jetty version 
> till 9.4.50 is impacted in a multipart issue. This is howwver fixed by jetty 
> in later versions. We use Apache Karaf that brings the Jetty through pax-web. 
> Please stepup the components so that the final karaf runtime has 9.4.51 Jetty 
> in it.
>  
> Other CVE [https://nvd.nist.gov/vuln/detail/CVE-2023-26049] is also fixed by 
> this stepup



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to