[MAVEN:GHSA-84Q7-P226-4X5W] Jetty vulnerable to cache poisoning due to inconsistent HTTP request handling (HTTP Request Smuggling)

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), contain an HTTP Request Smuggling Vulnerability that can result in cache poisoning.

Package Affected Version
pkg:maven/org.eclipse.jetty/jetty-server >= 9.4.0, <= 9.4.10.v20180503
pkg:maven/org.eclipse.jetty/jetty-server <= 9.3.23.v20180228
Package Fixed Version
pkg:maven/org.eclipse.jetty/jetty-server = 9.4.11.v20180605
pkg:maven/org.eclipse.jetty/jetty-server = 9.3.24.v20180605
ID
MAVEN:GHSA-84Q7-P226-4X5W
Severity
high
URL
https://github.com/advisories/GHSA-84q7-p226-4x5w
Published
2018-10-19T16:16:27
(6 years ago)
Modified
2023-01-31T05:03:09
(19 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.eclipse.jetty/jetty-server org.eclipse.jetty jetty-server >= 9.4.0 <= 9.4.10.v20180503
Fixed pkg:maven/org.eclipse.jetty/jetty-server org.eclipse.jetty jetty-server = 9.4.11.v20180605
Affected pkg:maven/org.eclipse.jetty/jetty-server org.eclipse.jetty jetty-server <= 9.3.23.v20180228
Fixed pkg:maven/org.eclipse.jetty/jetty-server org.eclipse.jetty jetty-server = 9.3.24.v20180605
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...