Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.153234
Category:Web Servers
Title:Eclipse Jetty URI Parsing Vulnerability (GHSA-qh8g-58pp-2wxh) - Linux
Summary:Eclipse Jetty is prone to an URI parsing vulnerability.
Description:Summary:
Eclipse Jetty is prone to an URI parsing vulnerability.

Vulnerability Insight:
Eclipse Jetty includes a utility class, HttpURI, for URI/URL
parsing.

The HttpURI class does insufficient validation on the authority segment of a URI. However the
behaviour of HttpURI differs from the common browsers in how it handles a URI that would be
considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may
differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and
a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI
is used after passing validation checks.

Affected Software/OS:
Eclipse Jetty version 7.0.0 through 12.0.11.

Solution:
Update to version 12.0.12 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2024-6763
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.