You are right, CVE-2011-XXXX first found to affect jetty (jetty 6) could
very well not be fixed in jetty 8 since jetty 8 was first released in 2009.


So to be on the safe side I checked the two CVEs from 2011.
CVE-2011-4461 affects 8.1.0-RC2 and earlier (later version exists in
jessie) and also marked as no-dsa (minor issue).
CVE-2011-4404 marked as duplicate of another CVE from 2009 and that problem
was solved in 2009.

With this said, yes we could mark these also for jetty8 for completeness,
but I do not see a big benefit.

