Skip to content

[GHSA-qh8g-58pp-2wxh] Eclipse Jetty URI parsing of invalid authority#5222

Closed
dwaller wants to merge 1 commit into
dwaller/advisory-improvement-5222from
dwaller-GHSA-qh8g-58pp-2wxh
Closed

[GHSA-qh8g-58pp-2wxh] Eclipse Jetty URI parsing of invalid authority#5222
dwaller wants to merge 1 commit into
dwaller/advisory-improvement-5222from
dwaller-GHSA-qh8g-58pp-2wxh

Conversation

@dwaller

@dwaller dwaller commented Jan 22, 2025

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3

Comments
CVE has been fixed in Jetty 9.4.57.v20241219, see commit on Nov 13, 2024 https://github.com/jetty/jetty.project/commits/jetty-9.4.57.v20241219/

@github

github commented Jan 22, 2025

Copy link
Copy Markdown
Collaborator

Hi there @joakime! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

Copilot AI review requested due to automatic review settings January 22, 2025 17:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

Files not reviewed (1)

@github-actions
github-actions Bot changed the base branch from main to dwaller/advisory-improvement-5222 January 22, 2025 17:42
@joakime

joakime commented Jan 22, 2025

Copy link
Copy Markdown

Duplicate of #5210

Reject.

This isn't the place to make this update. (This CVE is managed by the Eclipse Foundation)

We especially do not like this change to a EOL version of Jetty that NOBODY should be using now.

@joakime joakime left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reject.
See comment #5210 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants