CVE for Jetty 9 GZIP buffer release
<!--
There's help in the Eclipse Foundation Project Handbook https://www.eclipse.org/projects/handbook/#vulnerability-cve
Note that this issue is configured (see the quick actions at the bottom) to be created as confidential.
Note that a vulnerability does not need to actually be resolved before it is reported and that these reports can be revised as needed (reopen the issue to request changes).
If you do not know how to fill certain fields, mark that in the comment and we will help you.
You can delete the comments (or not).
-->
The Eclipse Foundation is a [Common Vulnerabilities and Exposures](https://cve.mitre.org/) (CVE) Numbering Authority. This issue it used to request and track the progress of the assignment of a CVE for a vulnerability in the project code for an Eclipse open source project.
## Basic information
**Project name:** Eclipse Jetty
**Project id:** jetty.project https://github.com/jetty/jetty.project
<!--
Required. Specify if you want a reservation only (in this case you may skip the fields below) or a publication (you need to fill all fields).
Please note that you can do the reservation first, then ask us for publication when the project has made a release with the fix.
-->
**Request type:** reservation/publication
<!--
Required (if publication). Specify the version range as precisely as possible, e.g., "[3.0, 3.5.1]" or "[3.0, 3.5.1)". Note that using the standard range notion, square brackets are inclusive (i.e., that version is included in the range), and round brakets are exclusive (the vulnerability affects all versions up to but not including the named version).
Multiple ranges can be provided.
-->
**Versions affected: >=9.4.0,<=9.4.56
**Common Weakness Enumeration:**
- [cwe-404](https://github.com/advisories?query=cwe%3A404)
**Common Vulnerability Scoring System:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
<!--
Required (if publication). The summary should start with the name of the project, e.g., "Eclipse Vert.x", then a description of the affected versions, followed by a description of the problem. The summary should be concise. For example,
"In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response
headers and HttpClient request headers do not filter carriage return and
line feed characters from the header value. This allow unfiltered values
to inject a new header in the client request or server response."
-->
**Summary:**
In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request
body. This can result in corrupted and/or inadvertent sharing of data between requests.
**Links:**
- https://github.com/jetty/jetty.project/security/advisories/GHSA-q4rv-gq96-w7c5
## Tracking
**This section will completed by the project team**.
- [x] Reserve an entry only
- [x] We're ready for this issue to be reported to the central authority (i.e., make this public now)
- [x] (when applicable) The GitHub Security Advisory is ready to be published now
Note that for those projects that host their repositories on GitHub, the use of GitHub Security Advisories is recommended but is not required.
**This section will be completed by the EMO**.
**CVE:** {cve}
- [ ] All required information is provided
- [ ] CVE Assigned
- [ ] Pushed to Mitre
- [ ] Accepted by Mitre
<!-- Quick actions will configure the state of the issue. Leave these. -->
issue