Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.151001
Category:Web Servers
Title:Eclipse Jetty HTTP Header Vulnerability (GHSA-hmr7-m48g-48f6) - Linux
Summary:Eclipse Jetty is prone to an HTTP header vulnerability.
Description:Summary:
Eclipse Jetty is prone to an HTTP header vulnerability.

Vulnerability Insight:
Jetty accepts the '+' character proceeding the content-length
value in a HTTP/1 header field. This is more permissive than allowed by the RFC and other servers
routinely reject such requests with 400 responses. There is no known exploit scenario, but it is
conceivable that request smuggling could result if jetty is used in combination with a server
that does not close the connection after sending such a 400 response.

Affected Software/OS:
Eclipse Jetty version 9.0.0 through 9.4.51, 10.0.0 through
10.0.15, 11.0.0 through 11.0.15 and version 12.0.0.

Solution:
Update to version 9.4.52, 10.0.16, 11.0.16, 12.0.1 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2023-40167
Debian Security Information: DSA-5507 (Google Search)
https://www.debian.org/security/2023/dsa-5507
https://github.com/eclipse/jetty.project/security/advisories/GHSA-hmr7-m48g-48f6
https://www.rfc-editor.org/rfc/rfc9110#section-8.6
https://lists.debian.org/debian-lts-announce/2023/09/msg00039.html
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.