Jetty for Windows installer updated to 12.0.20
Cantor, Scott
cantor.2 at osu.edu
Mon May 12 14:35:23 UTC 2025
There was a DoS vulnerability [1] in Jetty when HTTP/2 is enabled, which isn't really something we support in our packaging for Windows, but out of caution we have refreshed it to 12.0.20 as it was fairly stale anyway. [2]
Monitoring that download point is the main way to keep track but as always, running (and patching) your own container is strongly advised.
-- Scott
[1] https://www.eclipse.org/lists/jetty-announce/msg00198.html
[2] https://shibboleth.net/downloads/identity-provider/jetty-windows/
More information about the announce
mailing list