KAFKA-12400: Upgrade jetty to fix CVE-2020-27223
Here is the fix. The reason of [CVE-2020-27223](https://nvd.nist.gov/vuln/detail/CVE-2020-27223) was DOS vulnerability for Quoted Quality CSV headers and [patched in 9.4.37.v20210219](https://github.com/eclipse/jetty.project/security/advisories/GHSA-m394-8rww-3jr7).
This PR updates Jetty dependency into the following version, 9.4.38.v20210224.
Author: Lee Dongjin <dongjin@apache.org>
Reviewers: Manikumar Reddy <manikumar.reddy@gmail.com>
Closes #10245 from dongjinleekr/feature/KAFKA-12400
(cherry picked from commit b77deece1db3fca5575e336e157677f83bf3b506)
Signed-off-by: Manikumar Reddy <manikumar.reddy@gmail.com>
diff --git a/gradle/dependencies.gradle b/gradle/dependencies.gradle
index 90daf55..08270a8 100644
--- a/gradle/dependencies.gradle
+++ b/gradle/dependencies.gradle
@@ -69,7 +69,7 @@
jackson: "2.10.5",
jacksonDatabind: "2.10.5.1",
jacoco: "0.8.5",
- jetty: "9.4.36.v20210114",
+ jetty: "9.4.38.v20210224",
jersey: "2.31",
jmh: "1.23",
hamcrest: "2.2",