peter bassill · operator
$ cve CVE-2017-7658 JSON

CVE-2017-7658

9.8
CRITICAL · CVSS 3.1 · EPSS 19.4% (pctl 97)

Patch early

EPSS 19.4% — above the 10% action threshold.

Description

In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS19.36% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-444
On CISA KEVno
Public exploitnone known
Published2018-06-26
Last modified2026-06-17

Affected (20)

VendorProduct
debiandebian linux
eclipsejetty
hpxp p9000
hpxp p9000 command view
netappe-series santricity management
netappe-series santricity os controller
netappe-series santricity web services
netapphci management node
netapphci storage node
netapponcommand system manager
netapponcommand unified manager for 7-mode
netappsantricity cloud connector
netappsnap creator framework
netappsnapcenter
netappsnapmanager
netappsolidfire
netappstorage services connector
oraclerest data services
oracleretail xstore payment
oracleretail xstore point of service

References

→ the Explorer  ·  watch your stack  ·  NVD