-
Notifications
You must be signed in to change notification settings - Fork 498
[GHSA-qh8g-58pp-2wxh] Eclipse Jetty URI parsing of invalid authority #6537
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[GHSA-qh8g-58pp-2wxh] Eclipse Jetty URI parsing of invalid authority #6537
Conversation
|
Hi there @joakime! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
|
Reject. This is not fixed in the EOL releases of Jetty 9, Jetty 10, or Jetty 11. See past PRs on here for details. |
|
@joakime can you please refer to these PRs? |
|
In short, the HTTP RFC support levels in Jetty 9, Jerry 10, and Jerry 11 can not have the fix, as it would invalidate the older HTTP RFC those Jetty versions support. If you want/need the fix you must use Jetty 12.0+ This is why the CVE does not contain this fix listed for those old versions of Jetty. Also, the CVE is managed by the Eclipse CNA and cannot be updated by GitHub. |
|
This is not fixed in Jetty 9, Jetty 10, and Jetty 11. |
|
Keep in mind the Eclipse CNA also checks with the Eclipse project for proposed CVE fixes. We've addressed this multiple times with them as well. This advisory and CVE will is not, and will not, be fixed in Jetty 9, Jetty 10, and Jetty 11. |
1 similar comment
|
Keep in mind the Eclipse CNA also checks with the Eclipse project for proposed CVE fixes. We've addressed this multiple times with them as well. This advisory and CVE will is not, and will not, be fixed in Jetty 9, Jetty 10, and Jetty 11. |
|
I'll get the snyk report corrected again, as it is wrong. Blackduck, Tidelift, Mitre, and more have the correct information. |
|
hi @joakime , |
|
👋 Hi @amita-seal and @joakime, I'm going to keep the advisory as it currently is for now. If The Eclipse Foundation provides any more information in the record for https://www.cve.org/CVERecord?id=CVE-2024-6763 and/or GHSA-qh8g-58pp-2wxh, feel free to submit another PR. |
Updates
Comments
CVE-2024-6763
already implemented
source