Package
pinot
Component
jetty-http
Latest update
Fixed version
1.5.1-r0
3.7
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
1.5.1-r0Status
Impact
This CVE is only fixed in Jetty 12.0.12+. Pinot ships Jetty 9.4.x, which has no backport - the upstream advisory lists no 9.x fix. Fix gated on upstream pinot migrating from Jetty 9.4.x to Jetty 12.x, a major version migration.
Status