Jetty Vulnerabilities in Coldfusion 2018
During a vulnerability scan, my ColdFusion 2018 server was identified as having several Eclipse Jetty vulnerabilities. Will CF v13 be updated to address these? Or, will I have to manually upgrade Jetty -- and if so, how?
The host is installed with Eclipse Jetty Server and is prone to information disclosure vulnerability.
Installed version: 9.3.6.20151106
Fixed version: 9.3.24.v20180605
Product: cpe:/a:eclipse:jetty:9.3.6.20151106
Method: Jetty Version Detection (OID: 1.3.6.1.4.1.25623.1.0.800953)
Log: View details of product detection
CVE: CVE-2018-12536
CERT: DFN-CERT-2018-1285
Other: https://bugs.eclipse.org/bugs/show_bug.cgi?id=535670
https://www.eclipse.org/jetty/
------ and ------
The host is installed with Eclipse Jetty Server and is prone to security bypass vulnerability.
Installed version: 9.3.6.20151106
Fixed version: 9.3.24.v20180605
Product: cpe:/a:eclipse:jetty:9.3.6.20151106
Method: Jetty Version Detection (OID: 1.3.6.1.4.1.25623.1.0.800953)
Log: View details of product detection
CVE: CVE-2017-7658
CERT: DFN-CERT-2018-1285
Other: https://bugs.eclipse.org/bugs/show_bug.cgi?id=535669
https://www.eclipse.org/jetty/
