CVE-2017-7656

    Dashboard / Vulnerabilities / CVE-2017-7656

    CVE-2017-7656

    Published: 26 Jun 2018Last Modified: 6 Sept 2026

    Summary:

    Details: In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space version) that declares a version of HTTP/0.9 was accepted and treated as a 0.9 request. If deployed behind an intermediary that also accepted and passed through the 0.9 version (but did not act on it), then the response sent could be interpreted by the intermediary as HTTP/1 headers. This could be used to poison the cache if the server allowed the origin client to generate arbitrary content in the response.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    jetty-9.2.26.v20180806
    jetty-9.2.23.v20171218
    jetty-9.2.22.v20170606
    jetty-9.2.21.v20170120
    jetty-9.2.20.v20161216
    jetty-9.2.19.v20160908
    jetty-9.2.18.v20160721
    jetty-9.2.15.v20160210
    jetty-9.2.13.v20150730
    jetty-9.2.12.v20150709
    jetty-9.2.12.M0
    jetty-9.2.11.v20150529
    jetty-9.2.11.v20150528
    jetty-9.2.11.M0
    jetty-9.2.10.v20150310
    jetty-9.2.9.v20150224
    jetty-9.2.8.v20150217
    jetty-9.2.7.v20150116
    jetty-9.2.6.v20141205
    jetty-9.2.6.v20141203
    jetty-9.2.5.v20141112
    jetty-9.2.4.v20141103
    jetty-9.2.3.v20140905
    jetty-9.2.2.v20140723
    jetty-9.2.1.v20140609
    jetty-9.2.0.v20140526
    jetty-9.2.0.v20140523
    jetty-9.2.0.RC0
    jetty-9.2.0.M1
    jetty-9.2.0.M0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High