Package: jetty9 / 9.4.50-4+deb11u2

Metadata

Package Version Patches format
jetty9 9.4.50-4+deb11u2 3.0 (quilt)

Patch series

view the series file
Patch File delta Description
01 maven bundle plugin version.patch | (download)

pom.xml | 1 1 + 0 - 0 !
1 file changed, 1 insertion(+)

 maven-bundle-plugin-version


02 import alpn api.patch | (download)

jetty-alpn/jetty-alpn-api/pom.xml | 117 117 + 0 - 0 !
jetty-alpn/jetty-alpn-api/src/main/java/org/eclipse/jetty/alpn/ALPN.java | 249 249 + 0 - 0 !
jetty-alpn/pom.xml | 1 1 + 0 - 0 !
3 files changed, 367 insertions(+)

 add the one-class alpn api
 (http://git.eclipse.org/c/jetty/org.eclipse.jetty.alpn.git)


04 weksocket 1.1 compatibility.patch | (download)

jetty-websocket/javax-websocket-client-impl/src/main/java/org/eclipse/jetty/websocket/jsr356/JsrSession.java | 12 12 + 0 - 0 !
1 file changed, 12 insertions(+)

 fix the compatibility with the websocket api 1.1

06 ignore jetty documentation.patch | (download)

pom.xml | 1 0 + 1 - 0 !
1 file changed, 1 deletion(-)

 ignore the documentation module (removed from the upstream tarball
 to save some space)

07 assembly plugin configuration.patch | (download)

jetty-cdi/pom.xml | 6 3 + 3 - 0 !
jetty-websocket/javax-websocket-server-impl/pom.xml | 6 3 + 3 - 0 !
pom.xml | 6 3 + 3 - 0 !
3 files changed, 9 insertions(+), 9 deletions(-)

 modified the assembly plugin configuration to use
 debian/assembly-config.xml

08 ignore jetty test policy.patch | (download)

jetty-client/pom.xml | 2 1 + 1 - 0 !
1 file changed, 1 insertion(+), 1 deletion(-)

 don't unpack the test files from jetty-test-policy when building
 jetty-client

09 tweak distribution.patch | (download)

jetty-distribution/pom.xml | 12 6 + 6 - 0 !
jetty-home/pom.xml | 20 6 + 14 - 0 !
2 files changed, 12 insertions(+), 20 deletions(-)

 remove optional content from the distribution (documentation,
 sources, test files, examples)

servlet api.patch | (download)

jetty-home/pom.xml | 4 2 + 2 - 0 !
1 file changed, 2 insertions(+), 2 deletions(-)

 servlet api

CVE 2023 26048.patch | (download)

jetty-http/src/main/java/org/eclipse/jetty/http/MultiPartFormInputStream.java | 24 21 + 3 - 0 !
jetty-server/src/main/java/org/eclipse/jetty/server/MultiParts.java | 14 12 + 2 - 0 !
jetty-server/src/main/java/org/eclipse/jetty/server/Request.java | 27 23 + 4 - 0 !
jetty-servlet/src/test/java/org/eclipse/jetty/servlet/MultiPartServletTest.java | 141 141 + 0 - 0 !
jetty-util/src/main/java/org/eclipse/jetty/util/MultiPartInputStreamParser.java | 23 22 + 1 - 0 !
5 files changed, 219 insertions(+), 10 deletions(-)

 cve-2023-26048

CVE 2023 26049.patch | (download)

jetty-http/src/main/java/org/eclipse/jetty/http/CookieCompliance.java | 1 1 + 0 - 0 !
jetty-server/src/main/java/org/eclipse/jetty/server/CookieCutter.java | 102 67 + 35 - 0 !
jetty-server/src/test/java/org/eclipse/jetty/server/CookieCutterLenientTest.java | 3 2 + 1 - 0 !
jetty-server/src/test/java/org/eclipse/jetty/server/CookieCutterTest.java | 90 85 + 5 - 0 !
jetty-server/src/test/java/org/eclipse/jetty/server/RequestTest.java | 2 2 + 0 - 0 !
5 files changed, 157 insertions(+), 41 deletions(-)

 cve-2023-26049

CVE 2023 40167.patch | (download)

jetty-http/src/main/java/org/eclipse/jetty/http/HttpParser.java | 48 24 + 24 - 0 !
jetty-http/src/test/java/org/eclipse/jetty/http/HttpParserTest.java | 87 27 + 60 - 0 !
2 files changed, 51 insertions(+), 84 deletions(-)

 cve-2023-40167

CVE 2023 41900.patch | (download)

jetty-openid/src/main/java/org/eclipse/jetty/security/openid/OpenIdAuthenticator.java | 12 5 + 7 - 0 !
jetty-openid/src/main/java/org/eclipse/jetty/security/openid/OpenIdCredentials.java | 19 16 + 3 - 0 !
jetty-openid/src/test/java/org/eclipse/jetty/security/openid/OpenIdAuthenticationTest.java | 187 151 + 36 - 0 !
jetty-openid/src/test/java/org/eclipse/jetty/security/openid/OpenIdProvider.java | 250 216 + 34 - 0 !
4 files changed, 388 insertions(+), 80 deletions(-)

 cve-2023-41900

CVE 2023 36479.patch | (download)

jetty-servlets/src/main/java/org/eclipse/jetty/servlets/CGI.java | 3 3 + 0 - 0 !
tests/test-webapps/test-jetty-webapp/src/main/webapp/WEB-INF/web.xml | 12 0 + 12 - 0 !
2 files changed, 3 insertions(+), 12 deletions(-)

 cve-2023-36479


CVE 2023 44487.patch | (download)

jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/parser/ContinuationBodyParser.java | 36 26 + 10 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/parser/HeaderBlockFragments.java | 33 25 + 8 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/parser/HeadersBodyParser.java | 37 27 + 10 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/parser/Parser.java | 2 1 + 1 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/parser/PushPromiseBodyParser.java | 13 9 + 4 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/parser/ResetBodyParser.java | 8 5 + 3 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/parser/SettingsBodyParser.java | 29 20 + 9 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/parser/UnknownBodyParser.java | 1 0 + 1 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/ContinuationParseTest.java | 54 54 + 0 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/FrameFloodTest.java | 31 28 + 3 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/SettingsGenerateParseTest.java | 16 8 + 8 - 0 !
jetty-http2/http2-server/src/main/java/org/eclipse/jetty/http2/server/AbstractHTTP2ServerConnectionFactory.java | 2 1 + 1 - 0 !
12 files changed, 204 insertions(+), 58 deletions(-)

 cve-2023-44487

CVE 2023 36478.patch | (download)

jetty-http/src/main/java/org/eclipse/jetty/http/HttpTokens.java | 44 44 + 0 - 0 !
jetty-http/src/main/java/org/eclipse/jetty/http/compression/EncodingException.java | 27 27 + 0 - 0 !
jetty-http/src/main/java/org/eclipse/jetty/http/compression/Huffman.java | 357 357 + 0 - 0 !
jetty-http/src/main/java/org/eclipse/jetty/http/compression/HuffmanDecoder.java | 143 143 + 0 - 0 !
jetty-http/src/main/java/org/eclipse/jetty/http/compression/HuffmanEncoder.java | 142 142 + 0 - 0 !
jetty-http/src/main/java/org/eclipse/jetty/http/compression/NBitIntegerDecoder.java | 113 113 + 0 - 0 !
jetty-http/src/main/java/org/eclipse/jetty/http/compression/NBitIntegerEncoder.java | 96 96 + 0 - 0 !
jetty-http/src/main/java/org/eclipse/jetty/http/compression/NBitStringDecoder.java | 138 138 + 0 - 0 !
jetty-http/src/main/java/org/eclipse/jetty/http/compression/NBitStringEncoder.java | 82 82 + 0 - 0 !
jetty-http/src/test/java/org/eclipse/jetty/http/HuffmanTest.java | 168 168 + 0 - 0 !
jetty-http/src/test/java/org/eclipse/jetty/http/NBitIntegerTest.java | 207 207 + 0 - 0 !
jetty-http2/http2-client/src/main/java/org/eclipse/jetty/http2/client/HTTP2Client.java | 81 75 + 6 - 0 !
jetty-http2/http2-client/src/main/java/org/eclipse/jetty/http2/client/HTTP2ClientConnectionFactory.java | 83 66 + 17 - 0 !
jetty-http2/http2-client/src/main/java/org/eclipse/jetty/http2/client/HTTP2ClientSession.java | 10 9 + 1 - 0 !
jetty-http2/http2-client/src/test/java/org/eclipse/jetty/http2/client/HTTP2Test.java | 173 156 + 17 - 0 !
jetty-http2/http2-client/src/test/java/org/eclipse/jetty/http2/client/PrefaceTest.java | 13 6 + 7 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/HTTP2Connection.java | 22 16 + 6 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/HTTP2Session.java | 135 94 + 41 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/generator/Generator.java | 26 20 + 6 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/parser/HeaderBlockParser.java | 5 5 + 0 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/parser/HeadersBodyParser.java | 4 4 + 0 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/parser/Parser.java | 58 47 + 11 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/parser/PushPromiseBodyParser.java | 4 4 + 0 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/parser/ServerParser.java | 39 34 + 5 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/ContinuationParseTest.java | 7 3 + 4 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/DataGenerateParseTest.java | 13 6 + 7 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/FrameFloodTest.java | 7 3 + 4 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/GoAwayGenerateParseTest.java | 13 6 + 7 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/HeadersGenerateParseTest.java | 13 6 + 7 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/MaxFrameSizeParseTest.java | 9 4 + 5 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/PingGenerateParseTest.java | 19 9 + 10 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/PriorityGenerateParseTest.java | 13 6 + 7 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/PushPromiseGenerateParseTest.java | 13 6 + 7 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/ResetGenerateParseTest.java | 13 6 + 7 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/SettingsGenerateParseTest.java | 45 22 + 23 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/UnknownParseTest.java | 13 6 + 7 - 0 !
jetty-http2/http2-common/src/test/java/org/eclipse/jetty/http2/frames/WindowUpdateGenerateParseTest.java | 13 6 + 7 - 0 !
jetty-http2/http2-hpack/src/main/java/org/eclipse/jetty/http2/hpack/HpackContext.java | 61 32 + 29 - 0 !
jetty-http2/http2-hpack/src/main/java/org/eclipse/jetty/http2/hpack/HpackDecoder.java | 174 129 + 45 - 0 !
jetty-http2/http2-hpack/src/main/java/org/eclipse/jetty/http2/hpack/HpackEncoder.java | 174 87 + 87 - 0 !
jetty-http2/http2-hpack/src/main/java/org/eclipse/jetty/http2/hpack/HpackException.java | 5 2 + 3 - 0 !
jetty-http2/http2-hpack/src/main/java/org/eclipse/jetty/http2/hpack/HpackFieldPreEncoder.java | 14 5 + 9 - 0 !
jetty-http2/http2-hpack/src/main/java/org/eclipse/jetty/http2/hpack/Huffman.java | 551 0 + 551 - 0 !
jetty-http2/http2-hpack/src/main/java/org/eclipse/jetty/http2/hpack/MetaDataBuilder.java | 42 16 + 26 - 0 !
jetty-http2/http2-hpack/src/main/java/org/eclipse/jetty/http2/hpack/NBitInteger.java | 151 0 + 151 - 0 !
jetty-http2/http2-hpack/src/test/java/org/eclipse/jetty/http2/hpack/HpackContextTest.java | 33 31 + 2 - 0 !
jetty-http2/http2-hpack/src/test/java/org/eclipse/jetty/http2/hpack/HpackDecoderTest.java | 50 26 + 24 - 0 !
jetty-http2/http2-hpack/src/test/java/org/eclipse/jetty/http2/hpack/HpackEncoderTest.java | 30 20 + 10 - 0 !
jetty-http2/http2-hpack/src/test/java/org/eclipse/jetty/http2/hpack/HpackPerfTest.java | 29 17 + 12 - 0 !
jetty-http2/http2-hpack/src/test/java/org/eclipse/jetty/http2/hpack/HpackTest.java | 49 26 + 23 - 0 !
jetty-http2/http2-hpack/src/test/java/org/eclipse/jetty/http2/hpack/HuffmanTest.java | 87 0 + 87 - 0 !
jetty-http2/http2-hpack/src/test/java/org/eclipse/jetty/http2/hpack/NBitIntegerTest.java | 204 0 + 204 - 0 !
jetty-http2/http2-http-client-transport/src/test/java/org/eclipse/jetty/http2/client/http/HttpClientTransportOverHTTP2Test.java | 8 3 + 5 - 0 !
jetty-http2/http2-server/src/main/java/org/eclipse/jetty/http2/server/AbstractHTTP2ServerConnectionFactory.java | 85 70 + 15 - 0 !
jetty-http2/http2-server/src/main/java/org/eclipse/jetty/http2/server/HTTP2ServerConnection.java | 8 7 + 1 - 0 !
jetty-http2/http2-server/src/main/java/org/eclipse/jetty/http2/server/HTTP2ServerSession.java | 10 9 + 1 - 0 !
jetty-http2/http2-server/src/test/java/org/eclipse/jetty/http2/server/CloseTest.java | 19 9 + 10 - 0 !
jetty-http2/http2-server/src/test/java/org/eclipse/jetty/http2/server/HTTP2CServerTest.java | 13 6 + 7 - 0 !
jetty-http2/http2-server/src/test/java/org/eclipse/jetty/http2/server/HTTP2ServerTest.java | 45 22 + 23 - 0 !
jetty-util/src/main/java/org/eclipse/jetty/util/CharsetStringBuilder.java | 312 312 + 0 - 0 !
jetty-util/src/main/java/org/eclipse/jetty/util/StringUtil.java | 73 73 + 0 - 0 !
61 files changed, 3044 insertions(+), 1544 deletions(-)

 cve-2023-36478

CVE 2024 22201.patch | (download)

jetty-http2/http2-client/src/test/java/org/eclipse/jetty/http2/client/IdleTimeoutTest.java | 56 56 + 0 - 0 !
jetty-http2/http2-common/src/main/java/org/eclipse/jetty/http2/HTTP2Session.java | 14 13 + 1 - 0 !
2 files changed, 69 insertions(+), 1 deletion(-)

 cve-2024-22201