Package | jetty |
---|---|
Version | 6.1.26-4+deb8u2 |
Related CVEs | CVE-2021-28169 |
Steven Seeley discovered that in jetty, a Java servlet engine and webserver, requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory. An attacker may access sensitive information regarding the implementation of a web application.
This update also improves the fix to CVE-2017-9735 to cover more timing attacks.
For Debian 8 jessie, these problems have been fixed in version 6.1.26-4+deb8u2.
We recommend that you upgrade your jetty packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.