ColdFusion 2021 Update 5 installed Jetty CVEs
ColdFusion 2021 installed with the latest Update 5 has Jetty 9.4.31 installed inside of itself. I was working through another issue and was looking at the Jetty release notes when I started seeing multiple comments on resolved CVEs in the versions newer than the one in CF 2021. Most are Low and Moderate but two of them are classified as High.
- CVE-2020-27223
- CVE-2021-28163
- CVE-2021-28164
- CVE-2021-28165
- CVE-2021-28169
- CVE-2021-34428
- CVE-2021-34429
- CVE-2022-2047
- CVE-2022-2048
