11.0.15
joakime
released this
13 Apr 20:07
·
1005 commits
to jetty-11.0.x
since this release
Security Updates
This release addresses:
Changelog
- #9556 - Password Util does not ask for password
- #9555 - General bug fixes for jetty-start
- #9517 - Jetty 11.0.14 uses wrong pathSpec for request
- #9501 - jetty client with proxy - ssl traffic between both proxy and servers
- #9497 - Maven plugin add support for jar projects in
:effective-web-xml
- #9494 - Improved HttpClient TLS documentation about server host name verification
- #9468 - Jetty 11.0.14 is less tolerant of non-compliant cookies than 11.0.13
- #9464 - Add optional configuration to log user out after OpenID idToken expires (CVE-2023-41900)
- #9400 - Jetty logs warning with stacktrace when annotation parser encounters module-info.class file inside elasticsearch-x-content jar
- #9309 -
jetty.sh
cannot handle complex Jetty properties fromstart.d/*.ini
- #9237 - Decouple QTP
idleTimeout
from pool shrink rate - #6184 - Remove usages of classes associated with JEP-411 that deprecate/remove the SecurityManager from the JVM
Dependencies
- #9610 - Bump tycho-p2-repository-plugin to 3.0.4
- #9607 - Bump logback-core to 1.3.6
- #9596 - Bump org.eclipse.osgi.util to 3.7.200
- #9591 - Bump json-smart to 2.4.10
- #9581 - Bump commons-compress to 1.23.0
- #9575 - Bump protostream to 4.6.2.Final
- #9574 - Bump org.eclipse.osgi to 3.18.300
- #9558 - Bump asm.version to 9.5