{
    "id": "CVE-2017-7658",
    "published": "2018-06-26 17:29:00",
    "last_modified": "2026-06-17 01:24:54",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-444",
    "description": "In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.",
    "epss_score": "0.19362",
    "epss_percentile": "0.97281",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-03 18:17:19",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "EPSS 19.4% — above the 10% action threshold."
    },
    "products": [
        {
            "vendor": "debian",
            "product": "debian_linux"
        },
        {
            "vendor": "eclipse",
            "product": "jetty"
        },
        {
            "vendor": "hp",
            "product": "xp_p9000"
        },
        {
            "vendor": "hp",
            "product": "xp_p9000_command_view"
        },
        {
            "vendor": "netapp",
            "product": "e-series_santricity_management"
        },
        {
            "vendor": "netapp",
            "product": "e-series_santricity_os_controller"
        },
        {
            "vendor": "netapp",
            "product": "e-series_santricity_web_services"
        },
        {
            "vendor": "netapp",
            "product": "hci_management_node"
        },
        {
            "vendor": "netapp",
            "product": "hci_storage_node"
        },
        {
            "vendor": "netapp",
            "product": "oncommand_system_manager"
        },
        {
            "vendor": "netapp",
            "product": "oncommand_unified_manager_for_7-mode"
        },
        {
            "vendor": "netapp",
            "product": "santricity_cloud_connector"
        },
        {
            "vendor": "netapp",
            "product": "snap_creator_framework"
        },
        {
            "vendor": "netapp",
            "product": "snapcenter"
        },
        {
            "vendor": "netapp",
            "product": "snapmanager"
        },
        {
            "vendor": "netapp",
            "product": "solidfire"
        },
        {
            "vendor": "netapp",
            "product": "storage_services_connector"
        },
        {
            "vendor": "oracle",
            "product": "rest_data_services"
        },
        {
            "vendor": "oracle",
            "product": "retail_xstore_payment"
        },
        {
            "vendor": "oracle",
            "product": "retail_xstore_point_of_service"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "http://www.securityfocus.com/bid/106566",
        "http://www.securitytracker.com/id/1041194",
        "https://bugs.eclipse.org/bugs/show_bug.cgi?id=535669",
        "https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E",
        "https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E",
        "https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E",
        "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E",
        "https://lists.apache.org/thread.html/r41af10c4adec8d34a969abeb07fd0d6ad0c86768b751464f1cdd23e8%40%3Ccommits.druid.apache.org%3E",
        "https://lists.apache.org/thread.html/r9159c9e7ec9eac1613da2dbaddbc15691a13d4dbb2c8be974f42e6ae%40%3Ccommits.druid.apache.org%3E",
        "https://lists.apache.org/thread.html/ra6f956ed4ec2855583b2d0c8b4802b450f593d37b77509b48cd5d574%40%3Ccommits.druid.apache.org%3E",
        "https://security.netapp.com/advisory/ntap-20181014-0001/",
        "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03953en_us",
        "https://www.debian.org/security/2018/dsa-4278",
        "https://www.oracle.com//security-alerts/cpujul2021.html",
        "https://www.oracle.com/security-alerts/cpuoct2020.html",
        "https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html",
        "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html",
        "http://www.securityfocus.com/bid/106566",
        "http://www.securitytracker.com/id/1041194",
        "https://bugs.eclipse.org/bugs/show_bug.cgi?id=535669",
        "https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E",
        "https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E",
        "https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E",
        "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E",
        "https://lists.apache.org/thread.html/r41af10c4adec8d34a969abeb07fd0d6ad0c86768b751464f1cdd23e8%40%3Ccommits.druid.apache.org%3E"
    ]
}