apache / apache/beam

There is a vulnerability in Jetty: Java based HTTP/1.x, HTTP/2, Servlet, WebSocket Server 9.2.10.v20150310,upgrade recommended

Open
#22,906 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
8.7k
Forks
4.7k
Avg merge
1d 20h
Merged PRs (30d)
196

Description

https://github.com/apache/beam/blob/42b1640a25d5dbdea08ae2feaa0d3e81f6278575/runners/google-cloud-dataflow-java/worker/build.gradle#L108-L109

CVE-2017-7657 CVE-2017-7658 CVE-2021-28165 CVE-2020-27216 CVE-2017-9735

Recommended upgrade version:10.0.10

Contributor guide

Open the contributing guide

Research direction

Start at runners/google-cloud-dataflow-java/worker/build.gradle lines 108-109 and inspect the Jetty dependency declaration. Check the listed CVEs and the compatibility of the recommended Jetty version with this worker, then run the relevant Java worker or Gradle checks. Done means the vulnerable dependency is upgraded and verification passes.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
build-system, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.