Details
-
Fix
-
Status: Released (View Workflow)
-
Minor
-
Resolution: Fixed
-
2.5.8, 2.6.5
-
None
-
None
-
CVE-2024-22201
Description
Current Situation
- JS7 JOC Cockpit ships with Jetty 11.0.17
- A vulnerability affects this version: https://nvd.nist.gov/vuln/detail/CVE-2024-22201
Impact
- We rate the impact to our software being low as JS7 JOC ships with Jetty and the default usage of HTTP/1.
- Customers using HTTP/2 need to configure this on their own and therefore have to take appropriate measures themselves.
Desired Behavior
- JS7 JOC Cockpit should ship with the latest version 11.0.20 of Jetty which solves the vulnerability issue.