CWE-551
24 CVEs • Abstraction: Base
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
If a web server does not fully parse requested URLs before it examines them for authorization, it may be possible for an attacker to bypass authorization protection.
CVEs (24)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions when ext-authz extension is sending request headers to the external authorization serv...Show more |
3Eclipse NetappOracle18Autovue For Agile Product Lifecycle Management Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Security Edge Protection Proxy+15 moreJun 17, 2026 Jul 15, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a...Show more |
4Eclipse JenkinsNetapp+1 more21Autovue For Agile Product Lifecycle Management Cloud ManagerCommunications Cloud Native Core Policy+18 moreJun 17, 2026 Apr 1, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. |
3Eclipse NetappOracle17Autovue For Agile Product Lifecycle Management Banking ApisBanking Digital Experience+14 moreJun 17, 2026 Apr 1, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a r...Show more |