You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Three vulnerabilities have been dealt with according to the version of jetty-webapp:
CVE-20147-7658: already covered by upgrade from 9.2.25 to 9.4.8. CVE-2017-7657 also recommends > 9.2.25. CVE-2017-7656 is also covered by being > 9.3.23.
Two are NOT yet dealt with: CVE-2021-28165 requires upgrading from 9.4.8 to 9.4.39+, but is an issue of exhausting CPU resources so less severe. CVE-2020-27216 is not yet dealt with and appears more severe.
https://github.com/google/data-transfer-project/blob/ef53a7e92ef77a3efe0bdc378262215d0fe7498d/extensions/transport/portability-transport-jettyrest/build.gradle#L31
CVE-2017-7657 CVE-2017-7658 CVE-2021-28165 CVE-2020-27216 CVE-2017-7656
Recommended upgrade version:9.4.43.v20210629
The text was updated successfully, but these errors were encountered: