The Eclipse Foundation Eclipse Jetty vulnerabilities

23 known vulnerabilities affecting the_eclipse_foundation/eclipse_jetty.

Total CVEs
23
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH7MEDIUM10LOW3

Vulnerabilities

Page 2 of 2
CVE-2017-7657CRITICALCVSS 9.8≥ unspecified, ≤ 9.2.0≥ 9.3.0, < unspecified+3 more2018-06-26
CVE-2017-7657 [CRITICAL] CWE-444 CVE-2017-7657: In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default confi In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body
cvelistv5nvd
CVE-2017-7656HIGHCVSS 7.5≥ unspecified, ≤ 9.2.0≥ 9.3.0, < unspecified+3 more2018-06-26
CVE-2017-7656 [HIGH] CWE-444 CVE-2017-7656: In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default confi In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space version) that declares a version of HTTP/0.9 was accepted and treated as a 0.9 request. If deployed behind an intermediary tha
cvelistv5nvd
CVE-2018-12538HIGHCVSS 8.8≥ unspecified, < 9.4.9≥ 9.4.0, < unspecified2018-06-22
CVE-2018-12538 [HIGH] CWE-6 CVE-2018-12538: In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDat In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.
cvelistv5nvd