← Back

CVE-2017-7658

nvd nist
Published: Jun 26, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.

Affected (28)

Show all products
1 product
Jetty
1 product
Debian Linux
3 products
Rest Data Services
Retail Xstore Payment
Retail Xstore Point Of Service
1 product
Xp P9000 Command View
13 products
E Series Santricity Management
E Series Santricity Os Controller
E Series Santricity Web Services
Hci Management Node
Hci Storage Node
Oncommand System Manager
Santricity Cloud Connector
Snap Creator Framework
Snapcenter
Snapmanager
Solidfire
Storage Services Connector
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Eclipse
Up to 9.2.26
From 9.3.0 to 9.3.24
From 9.4.0 to 9.4.11
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration C
9 vulnerable
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 8.4.0-00 to 8.6.2-00
Running on/withPlatform Versions
Hp
Xp P9000
All versions
Configuration E
14 vulnerable

References (34)

Source: emo@eclipse.org
Third Party AdvisoryVDB Entry
Source: emo@eclipse.org
Third Party AdvisoryVDB Entry
Source: emo@eclipse.org
Third Party Advisory
Source: emo@eclipse.org
Third Party Advisory
Source: emo@eclipse.org
Third Party Advisory
Source: emo@eclipse.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.