Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-7658


In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.


Published

2018-06-26T17:29:00.210

Last Modified

2024-11-21T03:32:23.850

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-444
  • Type: Primary
    CWE-444

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application eclipse jetty ≤ 9.2.26 Yes
Application eclipse jetty < 9.3.24 Yes
Application eclipse jetty < 9.4.11 Yes
Operating System debian debian_linux 9.0 Yes
Application oracle rest_data_services 11.2.0.4 Yes
Application oracle rest_data_services 12.1.0.2 Yes
Application oracle rest_data_services 12.2.0.1 Yes
Application oracle rest_data_services 18c Yes
Application oracle retail_xstore_payment 3.3 Yes
Application oracle retail_xstore_point_of_service 7.1 Yes
Application oracle retail_xstore_point_of_service 15.0 Yes
Application oracle retail_xstore_point_of_service 16.0 Yes
Application oracle retail_xstore_point_of_service 17.0 Yes
Application hp xp_p9000_command_view ≤ 8.6.2-00 Yes
Hardware hp xp_p9000 - No
Application netapp e-series_santricity_management - Yes
Application netapp e-series_santricity_os_controller ≤ 11.50.1 Yes
Application netapp e-series_santricity_web_services - Yes
Application netapp hci_management_node - Yes
Application netapp hci_storage_node - Yes
Application netapp oncommand_system_manager ≤ 3.1.3 Yes
Application netapp oncommand_unified_manager_for_7-mode - Yes
Application netapp santricity_cloud_connector - Yes
Application netapp snap_creator_framework - Yes
Application netapp snapcenter - Yes
Application netapp snapmanager - Yes
Application netapp snapmanager - Yes
Application netapp solidfire - Yes
Application netapp storage_services_connector - Yes

References