Details
Description
HIgh jetty CVE https://nvd.nist.gov/vuln/detail/CVE-2022-2048 seems to be fixed in 9.4.47
The last ticket requesting update to jetty I found was https://issues.apache.org/jira/browse/ZOOKEEPER-4337 , but zk 3.5.10 currently is using
9.4.46.v20220331.jar
ztzg ddiederen could you please confirm I correctly filed this CVE issue? Thanks
Attachments
Issue Links
- blocks
-
ZOOKEEPER-4644 Update 3rd party library versions before release 3.6.4
- Closed
- relates to
-
ZOOKEEPER-4628 CVE-2022-42003 CVE-2022-42004 HIGH: upgrade jackson-databind-2.13.3.jar to 2.13.4.1
- Resolved
-
ZOOKEEPER-4337 CVE-2021-34429 in jetty 9.4.38.v20210224 in zookeeper 3.7.0
- Closed
- links to