SCA: security update for org.eclipse.jetty.ee10:jetty-ee10 (GHSA-gc59-r5jq-98qw)

high Tenable Self-Hosted Container Security Plugin ID 440065

Description

Duplicate Advisory: Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables

Solution

Update the org.eclipse.jetty.ee10:jetty-ee10 library and its related packages to version 10.0.28 or later.

See Also

https://github.com/advisories/GHSA-gc59-r5jq-98qw

Plugin Details

Severity: High

ID: 440065

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 4/8/2026

Updated: 4/16/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/8/2026

Vulnerability Publication Date: 4/8/2026

Reference Information

cwe: CWE-226