Описание
Security update for jetty-minimal
This update for jetty-minimal fixes the following issues:
- CVE-2025-11143: Fixed different parsing of invalid URIs (bsc#1259242).
Список пакетов
SUSE Linux Enterprise Module for Development Tools 15 SP7
jetty-http-9.4.58-150200.3.37.1
jetty-io-9.4.58-150200.3.37.1
jetty-security-9.4.58-150200.3.37.1
jetty-server-9.4.58-150200.3.37.1
jetty-servlet-9.4.58-150200.3.37.1
jetty-util-9.4.58-150200.3.37.1
jetty-util-ajax-9.4.58-150200.3.37.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
jetty-continuation-9.4.58-150200.3.37.1
openSUSE Leap 15.6
jetty-annotations-9.4.58-150200.3.37.1
jetty-ant-9.4.58-150200.3.37.1
jetty-cdi-9.4.58-150200.3.37.1
jetty-client-9.4.58-150200.3.37.1
jetty-continuation-9.4.58-150200.3.37.1
jetty-deploy-9.4.58-150200.3.37.1
jetty-fcgi-9.4.58-150200.3.37.1
jetty-http-9.4.58-150200.3.37.1
jetty-http-spi-9.4.58-150200.3.37.1
jetty-io-9.4.58-150200.3.37.1
jetty-jaas-9.4.58-150200.3.37.1
jetty-javax-websocket-client-impl-9.4.58-150200.3.37.1
jetty-javax-websocket-server-impl-9.4.58-150200.3.37.1
jetty-jmx-9.4.58-150200.3.37.1
jetty-jndi-9.4.58-150200.3.37.1
jetty-jsp-9.4.58-150200.3.37.1
jetty-minimal-javadoc-9.4.58-150200.3.37.1
jetty-openid-9.4.58-150200.3.37.1
jetty-plus-9.4.58-150200.3.37.1
jetty-project-9.4.58-150200.3.37.1
jetty-proxy-9.4.58-150200.3.37.1
jetty-quickstart-9.4.58-150200.3.37.1
jetty-rewrite-9.4.58-150200.3.37.1
jetty-security-9.4.58-150200.3.37.1
jetty-server-9.4.58-150200.3.37.1
jetty-servlet-9.4.58-150200.3.37.1
jetty-servlets-9.4.58-150200.3.37.1
jetty-start-9.4.58-150200.3.37.1
jetty-util-9.4.58-150200.3.37.1
jetty-util-ajax-9.4.58-150200.3.37.1
jetty-webapp-9.4.58-150200.3.37.1
jetty-websocket-api-9.4.58-150200.3.37.1
jetty-websocket-client-9.4.58-150200.3.37.1
jetty-websocket-common-9.4.58-150200.3.37.1
jetty-websocket-javadoc-9.4.58-150200.3.37.1
jetty-websocket-server-9.4.58-150200.3.37.1
jetty-websocket-servlet-9.4.58-150200.3.37.1
jetty-xml-9.4.58-150200.3.37.1
Ссылки
- Link for SUSE-SU-2026:1461-1
- E-Mail link for SUSE-SU-2026:1461-1
- SUSE Security Ratings
- SUSE Bug 1259242
- SUSE CVE CVE-2025-11143 page
Описание
The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.
Затронутые продукты
SUSE Linux Enterprise Module for Development Tools 15 SP7:jetty-http-9.4.58-150200.3.37.1
SUSE Linux Enterprise Module for Development Tools 15 SP7:jetty-io-9.4.58-150200.3.37.1
SUSE Linux Enterprise Module for Development Tools 15 SP7:jetty-security-9.4.58-150200.3.37.1
SUSE Linux Enterprise Module for Development Tools 15 SP7:jetty-server-9.4.58-150200.3.37.1
Ссылки
- CVE-2025-11143
- SUSE Bug 1259242