An open index of dependabot pull requests across open source projects.

org.eclipse.jetty:jetty-server

Ecosystem:
maven
Package URL:
pkg:maven/org.eclipse.jetty:jetty-server
Total PRs:
500 Dependabot PRs
Latest PR:
30 days ago
Unique Repositories:
232 repositories
Unique Repos (30 days):
3 repositories
Security Advisories
Improper Input Validation in Jetty
GHSA-qxp4-27vx-xmm3 CVE-2011-4461 MODERATE published about 4 years ago • updated 2 months ago
Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which ...
OutOfMemoryError for large multipart without filename in Eclipse Jetty
GHSA-qw69-rqj8-6qw8 CVE-2023-26048 MODERATE published about 3 years ago • updated 4 days ago
### Impact Servlets with multipart support (e.g. annotated with `@MultipartConfig`) that call `HttpServletRequest.getParameter()` or `HttpServletRe...
Jetty vulnerable to exposure of sensitive information due to observable discrepancy
GHSA-wfcc-pff6-rgc5 CVE-2017-9735 HIGH published over 7 years ago • updated 6 days ago
Jetty through 9.4.x contains a timing channel attack in `util/security/Password.java`, which allows attackers to obtain access by observing elapsed...
Installation information leak in Eclipse Jetty
GHSA-xc67-hjx6-cgg6 CVE-2019-10247 MODERATE published about 7 years ago • updated 4 days ago
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combina...
The Eclipse Jetty Server Artifact has a Gzip request memory leak
GHSA-xxh7-fcf3-rj7f CVE-2026-1605 HIGH published 3 months ago • updated 23 days ago
### Description (as reported) There is a memory leak when using `GzipHandler` in jetty-12.0.30 that can cause off-heap OOMs. This can be used for ...
Recent PRs (filtered by: Patch PRs )
Bump the maven group across 9 directories with 21 updates

yathin51/tutorials #18

9.4.19.v20190610 → 9.4.56.v20240826 Patch PR
Closed 4 months ago 1 comment
yathin51
Bump the maven group across 4 directories with 1 update

Cynive/NetworkDataAPI #4

9.4.48.v20220622 → 9.4.56.v20240826 Patch PR
Closed 7 months ago 2 comments
Cynive
Package Details
Name: org.eclipse.jetty:jetty-server
Ecosystem: maven
PURL Type: maven
Package URL: pkg:maven/org.eclipse.jetty:jetty-server
JSON API: View JSON
Security Advisories

26

Active advisories
CRITICAL 4
HIGH 9
MODERATE 11
LOW 2
View All maven Advisories
Package Information
Description:

The legacy jetty server artifact.

Repository: https://github.com/jetty/jetty.project
Homepage: https://jetty.org
Latest Release: 12.0.15
over 1 year ago
Dependent Repos: 34,580
Dependent Packages: 3,819
Ranking: Top 0.0272% by dependent repos Top 0.017% by dependent pkgs
PR Status
Open 196 (39.2%)
Merged 124 (24.8%)
Closed 130 (26.0%)
PR Types
Major 67 (13.4%)
Minor 54 (10.8%)
Patch 324 (64.8%)