There is a vulnerability in Jetty: Java based HTTP/1.x, HTTP/2, Servlet, WebSocket Server 9.2.10.v20150310,upgrade recommended
Open
- Dominant language
- Java
- Stars
- 8.7k
- Forks
- 4.7k
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 196
Description
https://github.com/apache/beam/blob/42b1640a25d5dbdea08ae2feaa0d3e81f6278575/runners/google-cloud-dataflow-java/worker/build.gradle#L108-L109
CVE-2017-7657 CVE-2017-7658 CVE-2021-28165 CVE-2020-27216 CVE-2017-9735
Recommended upgrade version:10.0.10
Contributor guide
Research direction
Start at runners/google-cloud-dataflow-java/worker/build.gradle lines 108-109 and inspect the Jetty dependency declaration. Check the listed CVEs and the compatibility of the recommended Jetty version with this worker, then run the relevant Java worker or Gradle checks. Done means the vulnerable dependency is upgraded and verification passes.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 35/100