[GitHub] [maven-dependency-plugin] dependabot[bot] opened a new pull request #91: Bump jettyVersion from 9.2.28.v20190418 to 9.3.0.v20150612

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
4 messages Options
Reply | Threaded
Open this post in threaded view
|

[GitHub] [maven-dependency-plugin] dependabot[bot] opened a new pull request #91: Bump jettyVersion from 9.2.28.v20190418 to 9.3.0.v20150612

GitBox

dependabot[bot] opened a new pull request #91:
URL: https://github.com/apache/maven-dependency-plugin/pull/91


   Bumps `jettyVersion` from 9.2.28.v20190418 to 9.3.0.v20150612.
   Updates `jetty-server` from 9.2.28.v20190418 to 9.3.0.v20150612
   
   Updates `jetty-servlet` from 9.2.28.v20190418 to 9.3.0.v20150612
   
   Updates `jetty-webapp` from 9.2.28.v20190418 to 9.3.0.v20150612
   
   
   Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
   
   
   </details>


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
[hidden email]


Reply | Threaded
Open this post in threaded view
|

[GitHub] [maven-dependency-plugin] slachiewicz commented on pull request #91: Bump jettyVersion from 9.2.28.v20190418 to 9.3.0.v20150612

GitBox

slachiewicz commented on pull request #91:
URL: https://github.com/apache/maven-dependency-plugin/pull/91#issuecomment-666403771


   CVE-2017-7656
   moderate severity
   Vulnerable versions: < 9.3.24.v20180605
   Patched version: 9.3.24.v20180605
   In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space version) that declares a version of HTTP/0.9 was accepted and treated as a 0.9 request. If deployed behind an intermediary that also accepted and passed through the 0.9 version (but did not act on it), then the response sent could be interpreted by the intermediary as HTTP/1 headers. This could be used to poison the cache if the server allowed the origin client to generate arbitrary content in the response.


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
[hidden email]


Reply | Threaded
Open this post in threaded view
|

[GitHub] [maven-dependency-plugin] dependabot[bot] commented on pull request #91: Bump jettyVersion from 9.2.28.v20190418 to 9.3.0.v20150612

GitBox
In reply to this post by GitBox

dependabot[bot] commented on pull request #91:
URL: https://github.com/apache/maven-dependency-plugin/pull/91#issuecomment-667509473


   OK, I won't notify you again about this release, but will get in touch when a new version is available.
   
   If you change your mind, just re-open this PR and I'll resolve any conflicts on it.


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
[hidden email]


Reply | Threaded
Open this post in threaded view
|

[GitHub] [maven-dependency-plugin] asfgit closed pull request #91: Bump jettyVersion from 9.2.28.v20190418 to 9.3.0.v20150612

GitBox
In reply to this post by GitBox

asfgit closed pull request #91:
URL: https://github.com/apache/maven-dependency-plugin/pull/91


   


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
[hidden email]