Hi Sebastien
You are right, CVE-2011-XXXX first found to affect jetty (jetty 6) could very well not be fixed in jetty 8 since jetty 8 was first released in 2009.
So to be on the safe side I checked the two CVEs from 2011.
CVE-2011-4461 affects 8.1.0-RC2 and earlier (later version exists in jessie) and also marked as no-dsa (minor issue).
CVE-2011-4404 marked as duplicate of another CVE from 2009 and that problem was solved in 2009.
With this said, yes we could mark these also for jetty8 for completeness, but I do not see a big benefit.
Best regards
// Ola