CVE-2023-40167
published 2023-09-15CVE-2023-40167: Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.07%
61.1th percentile
Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field. This is more permissive than allowed by the RFC and other servers routinely reject such requests with 400 responses. There is no known exploit scenario, but it is conceivable that request smuggling could result if jetty is used in combination with a server that does not close the connection after sending such a 400 response. Versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1 contain a patch for this issue. There is no workaround as there is no known exploit scenario.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | jetty9 | < jetty9 9.4.50-4+deb12u1 (bookworm) | jetty9 9.4.50-4+deb12u1 (bookworm) |
| eclipse | jetty | — | — |
| eclipse | jetty | >= 10.0.0 < 10.0.16 | 10.0.16 |
| eclipse | jetty | >= 11.0.0 < 11.0.16 | 11.0.16 |
| eclipse | jetty | >= 9.0.0 < 9.4.52 | 9.4.52 |
| eclipse | jetty.project | — | — |
| eclipse | jetty.project | — | — |
| eclipse | jetty.project | — | — |
| eclipse | jetty.project | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Retail Applications Risk Matrix: Point of Sale (Eclipse Jetty) — CVE-2023-40167
vendor_oracle·2025-04-15·CVSS 5.3
CVE-2023-40167 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Point of Sale (Eclipse Jetty) — CVE-2023-40167
Oracle Oracle Retail Applications Risk Matrix: Point of Sale (Eclipse Jetty) vulnerability
CVE: CVE-2023-40167
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Agent Next Gen (Eclipse Jetty) — CVE-2023-40167
vendor_oracle·2024-07-15·CVSS 5.3
CVE-2023-40167 [MEDIUM] Oracle Oracle Enterprise Manager Risk Matrix: Agent Next Gen (Eclipse Jetty) — CVE-2023-40167
Oracle Oracle Enterprise Manager Risk Matrix: Agent Next Gen (Eclipse Jetty) vulnerability
CVE: CVE-2023-40167
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (Eclipse Jetty) — CVE-2023-40167
vendor_oracle·2024-01-15·CVSS 5.3
CVE-2023-40167 [MEDIUM] Oracle Oracle Communications Risk Matrix: Configuration (Eclipse Jetty) — CVE-2023-40167
Oracle Oracle Communications Risk Matrix: Configuration (Eclipse Jetty) vulnerability
CVE: CVE-2023-40167
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Communications Risk Matrix: General (Eclipse Jetty) — CVE-2023-40167
vendor_oracle·2023-10-15·CVSS 5.3
CVE-2023-40167 [MEDIUM] Oracle Oracle Communications Risk Matrix: General (Eclipse Jetty) — CVE-2023-40167
Oracle Oracle Communications Risk Matrix: General (Eclipse Jetty) vulnerability
CVE: CVE-2023-40167
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Red Hat
jetty: Improper validation of HTTP/1 content-length
vendor_redhat·2023-09-19·CVSS 5.3
CVE-2023-40167 [MEDIUM] CWE-130 jetty: Improper validation of HTTP/1 content-length
jetty: Improper validation of HTTP/1 content-length
Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field. This is more permissive than allowed by the RFC and other servers routinely reject such requests with 400 responses. There is no known exploit scenario, but it is conceivable that request smuggling could result if jetty is used in combination with a server that does not close the connection after sending such a 400 response. Versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1 contain a patch for this issue. There is no workaround as there is no known exploit scenario.
A flaw was found in Jetty that permits a plus sign (+) preceding the content
Debian
CVE-2023-40167: jetty9 - Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 1...
vendor_debian·2023·CVSS 5.3
CVE-2023-40167 [MEDIUM] CVE-2023-40167: jetty9 - Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 1...
Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field. This is more permissive than allowed by the RFC and other servers routinely reject such requests with 400 responses. There is no known exploit scenario, but it is conceivable that request smuggling could result if jetty is used in combination with a server that does not close the connection after sending such a 400 response. Versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1 contain a patch for this issue. There is no workaround as there is no known exploit scenario.
Scope: local
bookworm: resolved (fixed in 9.4.50-4+deb12u1)
bullseye: resolved (fixed in 9.4.39-3+deb11u2)
forky: resolved (fixed
OSV
CVE-2023-40167: Jetty is a Java based web server and servlet engine
osv·2023-09-15·CVSS 5.3
CVE-2023-40167 [MEDIUM] CVE-2023-40167: Jetty is a Java based web server and servlet engine
Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field. This is more permissive than allowed by the RFC and other servers routinely reject such requests with 400 responses. There is no known exploit scenario, but it is conceivable that request smuggling could result if jetty is used in combination with a server that does not close the connection after sending such a 400 response. Versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1 contain a patch for this issue. There is no workaround as there is no known exploit scenario.
GHSA
Jetty accepts "+" prefixed value in Content-Length
ghsa·2023-09-14
CVE-2023-40167 [MEDIUM] CWE-130 Jetty accepts "+" prefixed value in Content-Length
Jetty accepts "+" prefixed value in Content-Length
### Impact
Jetty accepts the '+' character proceeding the content-length value in a HTTP/1 header field. This is more permissive than allowed by the RFC and other servers routinely reject such requests with 400 responses. There is no known exploit scenario, but it is conceivable that request smuggling could result if jetty is used in combination with a server that does not close the connection after sending such a 400 response.
### Workarounds
There is no workaround as there is no known exploit scenario.
### Original Report
[RFC 9110 Secion 8.6](https://www.rfc-editor.org/rfc/rfc9110#section-8.6) defined the value of Content-Length header should be a string of 0-9 digits. However we found that Jetty accepts "+" prefixed Content-Lengt
OSV
Jetty accepts "+" prefixed value in Content-Length
osv·2023-09-14
CVE-2023-40167 [MEDIUM] Jetty accepts "+" prefixed value in Content-Length
Jetty accepts "+" prefixed value in Content-Length
### Impact
Jetty accepts the '+' character proceeding the content-length value in a HTTP/1 header field. This is more permissive than allowed by the RFC and other servers routinely reject such requests with 400 responses. There is no known exploit scenario, but it is conceivable that request smuggling could result if jetty is used in combination with a server that does not close the connection after sending such a 400 response.
### Workarounds
There is no workaround as there is no known exploit scenario.
### Original Report
[RFC 9110 Secion 8.6](https://www.rfc-editor.org/rfc/rfc9110#section-8.6) defined the value of Content-Length header should be a string of 0-9 digits. However we found that Jetty accepts "+" prefixed Content-Lengt
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/eclipse/jetty.project/security/advisories/GHSA-hmr7-m48g-48f6https://lists.debian.org/debian-lts-announce/2023/09/msg00039.htmlhttps://www.debian.org/security/2023/dsa-5507https://www.rfc-editor.org/rfc/rfc9110#section-8.6https://github.com/eclipse/jetty.project/security/advisories/GHSA-hmr7-m48g-48f6https://lists.debian.org/debian-lts-announce/2023/09/msg00039.htmlhttps://www.debian.org/security/2023/dsa-5507https://www.rfc-editor.org/rfc/rfc9110#section-8.6
2023-09-15
Published