Skip to content

Conversation

@emerkle826
Copy link
Contributor

This patch removes CVE-2024-6763 as fixed in 6.8.58 and 6.9.10 as scan have shown there is still an older version of Jetty being shipped. This will be addressed in the next releases of each.


Release Notes Automation

If you name your pull-request as "Product x.y.z Release ...", after merging the
PR, a GitHub Action will automatically create a product version tag "product-x.y.z".

Supported product names are:

  • DSE
  • OpsCenter
  • Studio
  • Luna Streaming

Version supports 3 sets or 4 sets of digits.

@emerkle826
Copy link
Contributor Author

@brian-r-fisher I'm unsure if I should edit the PR name to product-x.y.z in this case as we just want to amend the existing release notes.

@emerkle826
Copy link
Contributor Author

@tiagomlalves I've simply removed the CVE from the release notes. Do we want to add a note, or do anything in addition? Or is simply removing the CVE from the notes sufficient?

This patch removes CVE-2024-6763 as fixed in 6.8.58 and 6.9.10 as scan
have shown there is still an older version of Jetty being shipped. This
will be addressed in the next releases of each.

Also, CVE-2024-47554 is removed as Apache commins-io version 2.8.0 is
still being pulled in via gremlin-console. This too will be addressed in
the next release of each.
@emerkle826 emerkle826 merged commit 300688c into master Feb 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants