Skip to content

KAFKA-12400: Upgrade jetty to fix CVE-2020-27223#10245

Closed
dongjinleekr wants to merge 1 commit into
apache:trunkfrom
dongjinleekr:feature/KAFKA-12400
Closed

KAFKA-12400: Upgrade jetty to fix CVE-2020-27223#10245
dongjinleekr wants to merge 1 commit into
apache:trunkfrom
dongjinleekr:feature/KAFKA-12400

Conversation

@dongjinleekr

Copy link
Copy Markdown
Contributor

Here is the fix. The reason of CVE-2020-27223 was DOS vulnerability for Quoted Quality CSV headers and patched in 9.4.37.v20210219.

This PR updates Jetty dependency into the following version, 9.4.38.v20210224.

Committer Checklist (excluded from commit message)

  • Verify design and implementation
  • Verify test coverage and CI build status
  • Verify documentation (including upgrade notes)

@dongjinleekr

Copy link
Copy Markdown
Contributor Author

@omkreddy @ijuma A follow-up of KAFKA-12324: Upgrade jetty to fix CVE-2020-27218. Should be cherry-picked into 2.8.0, 2.7.1, and 2.6.2.

@ableegoldman

Copy link
Copy Markdown
Member

What's the status here? Is this a blocker for the 2.6.2 release?

@dongjinleekr

Copy link
Copy Markdown
Contributor Author

@ableegoldman I think this should be a blocker, since it is security vulnerability.

@omkreddy omkreddy left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dongjinleekr Thanks for the PR. LGTM.

@omkreddy omkreddy closed this in b77deec Mar 3, 2021
omkreddy pushed a commit that referenced this pull request Mar 3, 2021
Here is the fix. The reason of [CVE-2020-27223](https://nvd.nist.gov/vuln/detail/CVE-2020-27223) was DOS vulnerability for Quoted Quality CSV headers and [patched in 9.4.37.v20210219](GHSA-m394-8rww-3jr7).

This PR updates Jetty dependency into the following version, 9.4.38.v20210224.

Author: Lee Dongjin <dongjin@apache.org>

Reviewers: Manikumar Reddy <manikumar.reddy@gmail.com>

Closes #10245 from dongjinleekr/feature/KAFKA-12400

(cherry picked from commit b77deec)
Signed-off-by: Manikumar Reddy <manikumar.reddy@gmail.com>
omkreddy pushed a commit that referenced this pull request Mar 3, 2021
Here is the fix. The reason of [CVE-2020-27223](https://nvd.nist.gov/vuln/detail/CVE-2020-27223) was DOS vulnerability for Quoted Quality CSV headers and [patched in 9.4.37.v20210219](GHSA-m394-8rww-3jr7).

This PR updates Jetty dependency into the following version, 9.4.38.v20210224.

Author: Lee Dongjin <dongjin@apache.org>

Reviewers: Manikumar Reddy <manikumar.reddy@gmail.com>

Closes #10245 from dongjinleekr/feature/KAFKA-12400

(cherry picked from commit b77deec)
Signed-off-by: Manikumar Reddy <manikumar.reddy@gmail.com>
omkreddy pushed a commit that referenced this pull request Mar 3, 2021
Here is the fix. The reason of [CVE-2020-27223](https://nvd.nist.gov/vuln/detail/CVE-2020-27223) was DOS vulnerability for Quoted Quality CSV headers and [patched in 9.4.37.v20210219](GHSA-m394-8rww-3jr7).

This PR updates Jetty dependency into the following version, 9.4.38.v20210224.

Author: Lee Dongjin <dongjin@apache.org>

Reviewers: Manikumar Reddy <manikumar.reddy@gmail.com>

Closes #10245 from dongjinleekr/feature/KAFKA-12400

(cherry picked from commit b77deec)
Signed-off-by: Manikumar Reddy <manikumar.reddy@gmail.com>
andrewegel pushed a commit to confluentinc/kafka that referenced this pull request Mar 18, 2021
Here is the fix. The reason of [CVE-2020-27223](https://nvd.nist.gov/vuln/detail/CVE-2020-27223) was DOS vulnerability for Quoted Quality CSV headers and [patched in 9.4.37.v20210219](GHSA-m394-8rww-3jr7).

This PR updates Jetty dependency into the following version, 9.4.38.v20210224.

Author: Lee Dongjin <dongjin@apache.org>

Reviewers: Manikumar Reddy <manikumar.reddy@gmail.com>

Closes apache#10245 from dongjinleekr/feature/KAFKA-12400

(cherry picked from commit b77deec)
Signed-off-by: Manikumar Reddy <manikumar.reddy@gmail.com>
xjin-Confluent pushed a commit to confluentinc/kafka that referenced this pull request Jun 1, 2021
Here is the fix. The reason of [CVE-2020-27223](https://nvd.nist.gov/vuln/detail/CVE-2020-27223) was DOS vulnerability for Quoted Quality CSV headers and [patched in 9.4.37.v20210219](GHSA-m394-8rww-3jr7).

This PR updates Jetty dependency into the following version, 9.4.38.v20210224.

Author: Lee Dongjin <dongjin@apache.org>

Reviewers: Manikumar Reddy <manikumar.reddy@gmail.com>

Closes apache#10245 from dongjinleekr/feature/KAFKA-12400

(cherry picked from commit b77deec)
Signed-off-by: Manikumar Reddy <manikumar.reddy@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants