Source: jetty9 Version: 9.4.39-2 Severity: grave Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>
Hi, The following vulnerability was published for jetty9. CVE-2021-34429[0]: | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & | 11.0.1-11.0.5, URIs can be crafted using some encoded characters to | access the content of the WEB-INF directory and/or bypass some | security constraints. This is a variation of the vulnerability | reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2021-34429 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34429 [1] https://github.com/eclipse/jetty.project/security/advisories/GHSA-vjv5-gp2w-65vm Please adjust the affected versions in the BTS as needed. Just from the upstream versions it is considered to be a problem starting with 9.4.37, but I have *not* checked if we might have an earlier patch introducing the issue, so please double check, but I suspect the only version so far affected is the one in bullseye/sid. Regards, Salvatore