[Git][security-tracker-team/security-tracker][master] Add note for CVE-2023-36479/jetty9

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 26 21:41:44 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
999ecaac by Salvatore Bonaccorso at 2023-09-26T22:38:41+02:00
Add note for CVE-2023-36479/jetty9

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1219,6 +1219,8 @@ CVE-2023-36479 (Eclipse Jetty Canonical Repository is the canonical repository f
 	- jetty9 <unfixed>
 	NOTE: https://github.com/eclipse/jetty.project/security/advisories/GHSA-3gh6-v5v9-6v9j
 	NOTE: https://github.com/eclipse/jetty.project/pull/9888
+	NOTE: Jetty 9.x, 10.x, and 11.x the org.eclipse.jetty.servlets.CGI has been deprecated
+	NOTE: and in Jetty 12 entirely removed.
 CVE-2023-36472 (Strapi is an open-source headless content management system. Prior to  ...)
 	NOT-FOR-US: Strapi
 CVE-2023-32461 (Dell PowerEdge BIOS and Dell Precision BIOS contain a buffer overflow  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/999ecaac9495ab70da4cd03225dc3b11f6b70fe8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/999ecaac9495ab70da4cd03225dc3b11f6b70fe8
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230926/5d270f43/attachment.htm>


More information about the debian-security-tracker-commits mailing list