You are viewing a plain text version of this content. The canonical link for it is here.
Posted to reviews@helix.apache.org by GitBox <gi...@apache.org> on 2020/12/04 08:04:55 UTC

[GitHub] [helix] QiAnXinCodeSafe opened a new issue #1571: There is a vulnerability in Jetty: Java based HTTP/1.x, HTTP/2, Servlet WebSocket Server 8.1.8.v20121106,upgrade recommended

QiAnXinCodeSafe opened a new issue #1571:
URL: https://github.com/apache/helix/issues/1571


   https://github.com/apache/helix/blob/2e30348d1447f0a107e6c19f59e38d37662787fa/pom.xml#L480
   
   CVE-2017-7658 CVE-2017-7657 CVE-2017-9735 CVE-2017-7656 CVE-2020-27216
   
   Recommended upgrade version:
   
   9.3.29.v20201019


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: reviews-unsubscribe@helix.apache.org
For additional commands, e-mail: reviews-help@helix.apache.org


[GitHub] [helix] junkaixue commented on issue #1571: There is a vulnerability in Jetty: Java based HTTP/1.x, HTTP/2, Servlet WebSocket Server 8.1.8.v20121106,upgrade recommended

Posted by GitBox <gi...@apache.org>.
junkaixue commented on issue #1571:
URL: https://github.com/apache/helix/issues/1571#issuecomment-895469240


   We do not have plan to do the upgrade right now. Close it.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: reviews-unsubscribe@helix.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: reviews-unsubscribe@helix.apache.org
For additional commands, e-mail: reviews-help@helix.apache.org


[GitHub] [helix] junkaixue closed issue #1571: There is a vulnerability in Jetty: Java based HTTP/1.x, HTTP/2, Servlet WebSocket Server 8.1.8.v20121106,upgrade recommended

Posted by GitBox <gi...@apache.org>.
junkaixue closed issue #1571:
URL: https://github.com/apache/helix/issues/1571


   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: reviews-unsubscribe@helix.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: reviews-unsubscribe@helix.apache.org
For additional commands, e-mail: reviews-help@helix.apache.org