Debian 9918 Published by

A jetty security update has been released for Debian GNU/Linux 8 Extended LTS to address an issue where requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory.



ELA-443-1 jetty security update

Package jetty
Version 6.1.26-4+deb8u2
Related CVEs CVE-2021-28169

Steven Seeley discovered that in jetty, a Java servlet engine and webserver, requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory. An attacker may access sensitive information regarding the implementation of a web application.

This update also improves the fix to CVE-2017-9735 to cover more timing attacks.

For Debian 8 jessie, these problems have been fixed in version 6.1.26-4+deb8u2.

We recommend that you upgrade your jetty packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-443-1 jetty security update