gitblit-org / gitblit

pure java git solution
http://gitblit.com
Apache License 2.0
2.28k stars 670 forks source link

The embedded Jetty servlet container has security issue #1390

Closed maorui2k closed 2 years ago

maorui2k commented 2 years ago

Here are details. Is there a new Gitblit package available? http://www.microsoft.com/zh-cn/download/details.aspx?FamilyID=73bb1c1e-29ad-47ba-818b-80e1a0ae2c20 https://bugs.eclipse.org/bugs/show_bug.cgi?id=535669

flaix commented 2 years ago

We can update the Jetty to 9.2.26.v20180806 and see if nothing else breaks by this update.

flaix commented 2 years ago

Seems there is also a version 9.2.30.v20200428