-
Notifications
You must be signed in to change notification settings - Fork 1.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Improve SSLConnection buffers handling (CVE-2022-2191) #8161
Comments
Signed-off-by: Ludovic Orban <[email protected]>
Signed-off-by: Ludovic Orban <[email protected]>
Signed-off-by: Ludovic Orban <[email protected]>
Signed-off-by: Ludovic Orban <[email protected]>
Signed-off-by: Ludovic Orban <[email protected]>
Signed-off-by: Ludovic Orban <[email protected]>
Signed-off-by: Ludovic Orban <[email protected]>
Signed-off-by: Ludovic Orban <[email protected]>
Signed-off-by: Ludovic Orban <[email protected]>
Signed-off-by: Ludovic Orban <[email protected]>
In light of discoveries during this review, a better combined ByteBufferPool with easier to configure setup was just merged in PR #8171, due for the next Jetty 10.0.x release. |
Does this also affect Jetty 9.x? According to the issue description this is only relevant for Jetty 10+ but the advisory says <= 10.0.9 which also includes version 9.x. |
No, it does not affect any 9.4.x version. |
Good catch! We'll update the advisory version range. |
affected versions in github advisories [(https://github.com/advisories/GHSA-8mpp-f3f7-xc28)] has < 10.0.10. |
See prior comments, and our advisory (the master database at github has not been updated yet):
Also, Jetty 9.4.x is now at End of Community Support, you are strongly encouraged to upgrade to Jetty 10+ as soon as possible. See: |
The github advisory database version of CVE-2022-2191 has its version range updated. |
Jetty version(s)
10+
Description
SSLConnection
's buffers utilization and their pooling should be reviewed.Fixes Security Advisory
GHSA-8mpp-f3f7-xc28
CVE-2022-2191
The text was updated successfully, but these errors were encountered: