[ 
https://issues.apache.org/jira/browse/SOLR-11213?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Gus Heck updated SOLR-11213:
----------------------------
    Security:     (was: Private (Security Issue))

> Update Jetty version to deal with CVE-2017-9735
> -----------------------------------------------
>
>                 Key: SOLR-11213
>                 URL: https://issues.apache.org/jira/browse/SOLR-11213
>             Project: Solr
>          Issue Type: Task
>            Reporter: Michael Braun
>            Priority: Major
>         Attachments: SOLR-11213.patch
>
>
> https://nvd.nist.gov/vuln/detail/CVE-2017-9735
> Original Jetty issue is at 
> https://github.com/eclipse/jetty.project/issues/1556
> Jetty through 9.4.x is prone to a timing channel in 
> util/security/Password.java. On the 9.3.x line, this has been fixed in 
> jetty-9.3.20.v20170531
> Jetty should be updated to this version to deal with this issue.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to