GHSA-vgg8-72f2-qm23

    Dashboard / Vulnerabilities / GHSA-vgg8-72f2-qm23

    GHSA-vgg8-72f2-qm23

    Published: 19 Oct 2018Last Modified: 17 Feb 2024
    Aliases:

    Summary: Critical severity vulnerability that affects org.eclipse.jetty:jetty-server

    Details: In Eclipse Jetty, versions 9.2.x and older, 9.3.x, transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.

    Affected packages

    Package

    Name: org.eclipse.jetty:jetty-server

    Purl: pkg:maven/org.eclipse.jetty/jetty-server

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -9.2.25.v20180606

    Affected versions

    7.0.0.M0
    7.0.0.M1
    7.0.0.M2
    7.0.0.M3
    7.0.0.M4
    7.0.0.RC0
    7.0.0.RC1
    7.0.0.RC2
    7.0.0.RC3
    7.0.0.RC4
    7.0.0.RC5
    7.0.0.RC6
    7.0.0.v20091005
    7.0.1.v20091125
    7.0.2.RC0
    7.0.2.v20100331

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High