[BUG]Eclipse Jetty组件存在安全漏洞
envgap__metersphere__metersphere-18298
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
7a2ca8d656c7caede4cd8c15c20ef08c2802742c- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
metersphere/metersphere #18298 · read the original issue
### 联系方式 15810415279@163.com ### MeterSphere 版本 V2.1.1 ### 使用外置数据库 否 ### 问题描述 近期公司启用漏扫工具发现MS平台引入的Eclipse Jetty组件存在安全漏洞,详细内容再见下文: 1、漏洞问题1描述: 【CVE-2022-2047】 Eclipse Jetty 存在安全漏洞,该漏洞源于无效的 URI 解析可能会产生无效的 HttpURI.authority,以下产品和版本受到影响:Eclipse Jetty 9.4.46及之前版本、10.0.9 及之前版本、11.0.9及之前版本。 【修复建议】 厂商补丁: 已发布升级补丁以修复漏洞,补丁获取链接: https://github.com/eclipse/jetty.project/security/advisories/GHSA-cj7v-27pg-wf7q 2、漏洞问题1描述: 【CVE-2022-2048】 Eclipse Jetty 存在安全漏洞,该漏洞源于无效的 HTTP/2 请求可能导致拒绝服务,以下产品和版本受到影响:Eclipse Jetty 9.4.46及之前版本、10.0.9 及之前版本、11.0.9及之前版本。 【修复建议】 厂商补丁: 已发布升级补丁以修复漏洞,补丁获取链接: https://github.com/eclipse/jetty.project/security/advisories/GHSA-wgmr-mf83-7x4j ### 重现步骤 公司可能暂停ms服务,建议尽快升级组件,谢谢 ### 期待的正确结果 _No response_ ### 相关日志输出 _No response_ ### 附加信息 _No response_
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]