Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
PRODUCT FAMILYSERVER APPLICATIONPARTIAL

Jetty

Eclipse Jetty

Eclipse Jetty is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Lifecycle status

No support or retirement date is shown unless BlackTree can link it to a registered publisher source. A missing date means that a boundary is not publicly stated, has not yet been extracted, or still needs source routing. It does not mean the product is supported indefinitely.

Product overview

Eclipse Jetty is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Networked or application service delivery
  • Administrative and operational interfaces
  • Versioned maintenance and security updates

Typical use

Used to provide application, infrastructure or operational services to other systems and users.

Deployment

Deployed on servers, virtual machines, containers or managed infrastructure.

Lifecycle records

ReleaseBoundaryDate
Lifecycle policyOfficial lifecycle policy; no bounded date foundNot dated by publisher

Official sources

PARTIAL

Eclipse Jetty official lifecycle source

Checked automatically.

Extracted 1 lifecycle record(s), including 0 bounded date record(s), from the registered official source.

Open publisher source

Package vulnerability advisories

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

Fixed: 10.0.23, 11.0.23

Jetty SslConnection does not release pooled ByteBuffers in case of errors

Fixed: 10.0.10, 11.0.10

Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resources

Fixed: 9.4.39, 10.0.2, 11.0.2

Eclipse Jetty: HTTP Authority/Host mismatch

Fixed: 12.0.35, 12.1.9

Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections

Fixed: 12.0.36, 12.1.10

Buffer not correctly recycled in Gzip Request inflation

Fixed: 9.4.35.v20201120

DOS vulnerability for Quoted Quality CSV headers

Fixed: 9.4.37, 10.0.1, 11.0.1

SessionListener can prevent a session from being invalidated breaking logout

Fixed: 9.4.41, 10.0.3, 11.0.3