CVE-2017-7656 – org.eclipse.jetty:jetty-server
Package
Manager: maven
Name: org.eclipse.jetty:jetty-server
Vulnerable Version: >=0 <9.3.24.v20180605 || >=9.4.0 <9.4.11.v20180605
Severity
Level: High
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS: 0.03903 pctl0.87827
Details
Jetty vulnerable to cache poisoning due to inconsistent HTTP request handling (HTTP Request Smuggling) Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), contain an HTTP Request Smuggling Vulnerability that can result in cache poisoning.
Metadata
Created: 2018-10-19T16:16:27Z
Modified: 2022-09-14T01:08:10Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-84q7-p226-4x5w/GHSA-84q7-p226-4x5w.json
CWE IDs: ["CWE-444"]
Alternative ID: GHSA-84q7-p226-4x5w
Finding: F110
Auto approve: 1