ELA-429-1 jetty security update

multiple vulnerabilities

2021-05-14
Packagejetty
Version6.1.26-4+deb8u1
Related CVEs CVE-2017-9735 CVE-2019-10247


It was discovered that jetty, a Java servlet engine and webserver, is vulnerable to a timing attack and an information leak. An attacker might reveal cryptographic credentials such as passwords to a local user, or disclose webapps installation path.



For Debian 8 jessie, these problems have been fixed in version 6.1.26-4+deb8u1.

We recommend that you upgrade your jetty packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.