From 4b3354e6f854f17e1d66d38ba419c8d86ae8dee357b04be3e7a719389e98d602 Mon Sep 17 00:00:00 2001 From: Fridrich Strba Date: Tue, 27 Feb 2024 12:30:58 +0000 Subject: [PATCH] OBS-URL: https://build.opensuse.org/package/show/Java:packages/jetty-minimal?expand=0&rev=76 --- jetty-minimal.changes | 11 +++++++++++ jetty-minimal.spec | 8 ++++---- jetty-unixsocket.changes | 11 +++++++++++ jetty-unixsocket.spec | 8 ++++---- jetty-websocket.changes | 11 +++++++++++ jetty-websocket.spec | 8 ++++---- jetty.project-jetty-9.4.53.v20231009.tar.gz | 3 --- jetty.project-jetty-9.4.54.v20240208.tar.gz | 3 +++ 8 files changed, 48 insertions(+), 15 deletions(-) delete mode 100644 jetty.project-jetty-9.4.53.v20231009.tar.gz create mode 100644 jetty.project-jetty-9.4.54.v20240208.tar.gz diff --git a/jetty-minimal.changes b/jetty-minimal.changes index dfd1b43..58fce8c 100644 --- a/jetty-minimal.changes +++ b/jetty-minimal.changes @@ -1,3 +1,14 @@ +------------------------------------------------------------------- +Tue Feb 27 12:27:27 UTC 2024 - Fridrich Strba + +- Upgrade to version 9.4.54.v20240208 + * Security fixes + + CVE-2024-22201, bsc#1220437: HTTP/2 connection not closed + after idle timeout when TCP congested + * Other changes + + #1256 DoSFilter leaks USER_AUTH entries + + #11389 Strip default ports on ws/wss scheme uris too + ------------------------------------------------------------------- Mon Oct 30 16:17:21 UTC 2023 - Fridrich Strba diff --git a/jetty-minimal.spec b/jetty-minimal.spec index a7f8365..6403ac9 100644 --- a/jetty-minimal.spec +++ b/jetty-minimal.spec @@ -1,7 +1,7 @@ # -# spec file +# spec file for package jetty-minimal # -# Copyright (c) 2023 SUSE LLC +# Copyright (c) 2024 SUSE LLC # Copyright (c) 2000-2007, JPackage Project # # All modifications and additions to the file contributed by third parties @@ -18,10 +18,10 @@ %global base_name jetty -%global addver .v20231009 +%global addver .v20240208 %define src_name %{base_name}.project-%{base_name}-%{version}%{addver} Name: %{base_name}-minimal -Version: 9.4.53 +Version: 9.4.54 Release: 0 Summary: Java Webserver and Servlet Container License: Apache-2.0 OR EPL-1.0 diff --git a/jetty-unixsocket.changes b/jetty-unixsocket.changes index d8d4776..9ac2594 100644 --- a/jetty-unixsocket.changes +++ b/jetty-unixsocket.changes @@ -1,3 +1,14 @@ +------------------------------------------------------------------- +Tue Feb 27 12:27:27 UTC 2024 - Fridrich Strba + +- Upgrade to version 9.4.54.v20240208 + * Security fixes + + CVE-2024-22201, bsc#1220437: HTTP/2 connection not closed + after idle timeout when TCP congested + * Other changes + + #1256 DoSFilter leaks USER_AUTH entries + + #11389 Strip default ports on ws/wss scheme uris too + ------------------------------------------------------------------- Thu Oct 12 15:51:00 UTC 2023 - Fridrich Strba diff --git a/jetty-unixsocket.spec b/jetty-unixsocket.spec index 9400883..f81c3f7 100644 --- a/jetty-unixsocket.spec +++ b/jetty-unixsocket.spec @@ -1,7 +1,7 @@ # -# spec file +# spec file for package jetty-unixsocket # -# Copyright (c) 2023 SUSE LLC +# Copyright (c) 2024 SUSE LLC # Copyright (c) 2000-2007, JPackage Project # # All modifications and additions to the file contributed by third parties @@ -18,10 +18,10 @@ %global base_name jetty -%global addver .v20231009 +%global addver .v20240208 %define src_name %{base_name}.project-%{base_name}-%{version}%{addver} Name: %{base_name}-unixsocket -Version: 9.4.53 +Version: 9.4.54 Release: 0 Summary: The unixsocket modules for Jetty License: Apache-2.0 OR EPL-1.0 diff --git a/jetty-websocket.changes b/jetty-websocket.changes index 01f651f..8f6ab79 100644 --- a/jetty-websocket.changes +++ b/jetty-websocket.changes @@ -1,3 +1,14 @@ +------------------------------------------------------------------- +Tue Feb 27 12:27:27 UTC 2024 - Fridrich Strba + +- Upgrade to version 9.4.54.v20240208 + * Security fixes + + CVE-2024-22201, bsc#1220437: HTTP/2 connection not closed + after idle timeout when TCP congested + * Other changes + + #1256 DoSFilter leaks USER_AUTH entries + + #11389 Strip default ports on ws/wss scheme uris too + ------------------------------------------------------------------- Thu Oct 12 15:51:00 UTC 2023 - Fridrich Strba diff --git a/jetty-websocket.spec b/jetty-websocket.spec index bda3fe6..8c2c963 100644 --- a/jetty-websocket.spec +++ b/jetty-websocket.spec @@ -1,7 +1,7 @@ # -# spec file +# spec file for package jetty-websocket # -# Copyright (c) 2023 SUSE LLC +# Copyright (c) 2024 SUSE LLC # Copyright (c) 2000-2007, JPackage Project # # All modifications and additions to the file contributed by third parties @@ -18,10 +18,10 @@ %global base_name jetty -%global addver .v20231009 +%global addver .v20240208 %define src_name %{base_name}.project-%{base_name}-%{version}%{addver} Name: %{base_name}-websocket -Version: 9.4.53 +Version: 9.4.54 Release: 0 Summary: The websocket modules for Jetty License: Apache-2.0 OR EPL-1.0 diff --git a/jetty.project-jetty-9.4.53.v20231009.tar.gz b/jetty.project-jetty-9.4.53.v20231009.tar.gz deleted file mode 100644 index b78049c..0000000 --- a/jetty.project-jetty-9.4.53.v20231009.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:fcff12abe2702029cc1bcd75a7294c0359f243fb16768c5d9f161a9b2fa3c7ee -size 19349292 diff --git a/jetty.project-jetty-9.4.54.v20240208.tar.gz b/jetty.project-jetty-9.4.54.v20240208.tar.gz new file mode 100644 index 0000000..474db7a --- /dev/null +++ b/jetty.project-jetty-9.4.54.v20240208.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:51201322d72c5ef29c0ae83ef130a3b58460a41935e38c7830c26deece87473f +size 19349613