Skip to content

False positive reported on Jetty CVE-2025-5115 — version is at fix version #448

@rrgupta-jii

Description

@rrgupta-jii

Describe the bug
Xray reports CVE-2025-5115 against org.eclipse.jetty:jetty-server:9.4.58. This CVE affects Jetty ≤9.4.57. The fix version is 9.4.58 — which is exactly our version. We are patched.

To Reproduce
Xray scan a software containing jetty-server 9.4.58 and see CVE-2025-5115 reported. This CVE was fixed in 9.4.58.

Expected behavior
CVE-2025-5115 should not be reported for Jetty >= 9.4.58, as 9.4.58 is the fix version.

Versions

  • Package: org.eclipse.jetty:jetty-server:9.4.58
  • Vulnerable range: ≤9.4.57
  • Fix version: 9.4.58

Additional context
Advisory: GHSA-mmxm-8w33-wc4h

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions