Jetty EOL / vulnerabilities

  • I’m using SCM-Manager 3.11.10 (latest version available) and after running a security check, it was detected some security issues related with Jetty (print screen attacted). I also notice that jetty 11 is EOL. Is there any plans to upgrade to current version (12)?

  • expected result / system behavior: maintain dependencies up to date if possible

  • observed result / system behavior: dependencies with security issues/eol.

  • SCM-Manager version and installed package: SCM-Manager 3.11.10

Hi @danielnovo , thanks for this hint!

Your security check leaves me confused. In SCM-Manager 3.11.10 we use Jetty in version 11.0.26. This version should not be affected by the CVE you mention. It would be nice if you could check this once more.

Nonetheless, last week we finished the update to Jetty 12 for our next development iteration, version 4.x. But unless there really is an issue with our Jetty version in 3.x, I would keep it at version 11 to avoid issues with the migration (Jetty 12 has had some new concepts and introducing a risk of different configurations would better fit to a 4.x).

I hope this helps. Regards

René