peter bassill · operator
$ cve CVE-2017-7657 JSON

CVE-2017-7657

9.8
CRITICAL · CVSS 3.1 · EPSS 14.9% (pctl 97)

Patch early

EPSS 14.9% — above the 10% action threshold.

Description

In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS14.88% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-444
On CISA KEVno
Public exploitnone known
Published2018-06-26
Last modified2026-06-17

Affected (18)

VendorProduct
debiandebian linux
eclipsejetty
hpxp p9000
hpxp p9000 command view
netappe-series santricity management
netappe-series santricity os controller
netappe-series santricity web services
netappelement software
netappelement software management node
netapphci storage nodes
netapponcommand system manager
netapponcommand unified manager
netappsantricity cloud connector
netappsnap creator framework
netappsnapcenter
netappsnapmanager
oraclerest data services
oracleretail xstore point of service

References

→ the Explorer  ·  watch your stack  ·  NVD