-
Notifications
You must be signed in to change notification settings - Fork 1.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Questions about CVE-2024-6763 in Jetty 10 #12581
Comments
That is an informational CVE, read it carefully. The Jetty Server and Jetty Client on all releases of Jetty 12/11/10/9 are not vulnerable. Only direct use of HttpURI in your own application, under VERY specific conditions, would you be vulnerable. Either:
That is the solution. The change you see in Jetty 12 doesn't fix this, it merely ignores the user-info section. There is nothing in Jetty Server or Jetty Client that supports user-info anyway. |
Also, note that Jetty 10 is EOL on January 1, 2025. You should be moving to a supported version of Jetty at this point in time, Jetty 12 for example. |
Got it. Thanks. |
Closed. |
Jetty 10
Is it planned to fix the following vulnerabilities in Jetty 10:
CVE-2024-6763 | medium | org.eclipse.jetty_jetty-io | 10.0.24
CVE-2024-6763 | medium | org.eclipse.jetty_jetty-http | 10.0.24
The text was updated successfully, but these errors were encountered: