camel-jetty-starter引入jetty-http存CVE-2022-2047漏洞及升级问题
漏洞详情
jetty-http-9.4.46.v20220331.jar | Reference: CVE-2022-2047 | CVSS Score: 2.7 | Category: CWE-20 | In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
依赖溯源
漏洞依赖来自:
implementation 'org.apache.camel.springboot:camel-jetty-starter:3.14.5'
相关依赖树片段:
--- org.apache.camel.springboot:camel-jetty-starter:3.14.5 | +--- org.springframework.boot:spring-boot-starter:2.6.10 -> 2.7.0 (*) | +--- org.apache.camel:camel-jetty:3.14.5 | | +--- org.apache.camel:camel-support:3.14.5 (*) | | +--- org.apache.camel:camel-http-common:3.14.5 | | | +--- org.apache.camel:camel-http-base:3.14.5 | | | | \--- org.apache.camel:camel-support:3.14.5 (*) | | | +--- org.apache.camel:camel-cloud:3.14.5 (*) | | | +--- org.apache.camel:camel-support:3.14.5 (*) | | | \--- org.apache.camel:camel-attachments:3.14.5 | | | +--- org.apache.camel:camel-support:3.14.5 (*) | | | \--- com.sun.activation:javax.activation:1.2.0 | | +--- org.apache.camel:camel-jetty-common:3.14.5 | | | +--- org.apache.camel:camel-cloud:3.14.5 (*) | | | +--- org.apache.camel:camel-http-common:3.14.5 (*) | | | \--- javax.servlet:javax.servlet-api:3.1.0 -> 4.0.1 | | +--- org.eclipse.jetty:jetty-server:9.4.46.v20220331 | | | +--- javax.servlet:javax.servlet-api:3.1.0 -> 4.0.1 | | | +--- org.eclipse.jetty:jetty-http:9.4.46.v20220331 | | | | +--- org.eclipse.jetty:jetty-util:9.4.46.v20220331 | | | | \--- org.eclipse.jetty:jetty-io:9.4.46.v20220331 | | | | \--- org.eclipse.jetty:jetty-util:9.4.46.v20220331 | | | \--- org.eclipse.jetty:jetty-io:9.4.46.v20220331 (*)
问题场景
尝试直接添加高版本Jetty HTTP依赖修复漏洞:
implementation 'org.apache.camel.springboot:camel-jetty-starter:3.14.5' implementation 'org.eclipse.jetty:jetty-http:11.0.11'
但Eclipse提示依赖无法解析。
解决方案
1. 确认仓库配置
确保Gradle构建脚本中包含Maven Central仓库(Jetty组件托管在此):
repositories { mavenCentral() }
2. 统一指定Jetty安全版本
Jetty组件版本强绑定,单独升级jetty-http会引发版本冲突。Camel 3.14.5基于Jetty 9.x开发,跨版本升级到11.x会触发API兼容问题,因此应选择9.4.x系列的最新安全版本(9.4.48及以上已修复CVE-2022-2047),通过Gradle的版本强制策略统一升级:
configurations.all { resolutionStrategy { force 'org.eclipse.jetty:jetty-http:9.4.48.v20220622' force 'org.eclipse.jetty:jetty-server:9.4.48.v20220622' force 'org.eclipse.jetty:jetty-io:9.4.48.v20220622' force 'org.eclipse.jetty:jetty-util:9.4.48.v20220622' } }
3. 验证依赖升级结果
执行以下命令确认Jetty组件版本已替换为指定的安全版本:
./gradlew dependencies --configuration runtimeClasspath | grep jetty
4. 刷新Eclipse缓存
若Eclipse仍报错,执行以下操作:
- 右键项目 → Gradle → Refresh Gradle Project
- 项目菜单 → Clean... → 选择当前项目 → 点击Clean
内容的提问来源于stack exchange,提问作者Ricky V.

