Package
pinot
Component
jetty-http
Latest update
Fixed version
1.5.1-r0
7.4
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
1.5.1-r0Status
Impact
jetty-http 9.4.60 (the fix for this CVE) is not published to Maven Central. Post-EOL Jetty 9.4.x security fixes are released only through Webtide's commercial maintenance program. Fix gated on upstream pinot migrating to a supported Jetty branch (12.x).
Status