Closed ashibhardwaj closed 5 days ago
Upgrading jetty from version 9.4.54.v20240208 to 9.4.56.v20240826 to fix CVE-2024-8184.
9.4.54.v20240208
9.4.56.v20240826
Refer: https://avd.aquasec.com/nvd/cve-2024-8184 (org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks)
Hi @ashibhardwaj, thanks for contributing to Druid! It appears that this change is already included in the following patch by @findingrish: https://github.com/apache/druid/pull/17385.
Upgrading jetty from version
9.4.54.v20240208
to9.4.56.v20240826
to fix CVE-2024-8184.Refer: https://avd.aquasec.com/nvd/cve-2024-8184 (org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks)