CRITICAL · 9.8

CVE-2017-7658

In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the ...

Vulnerability Description

In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
EclipseJetty<= 9.2.26
DebianDebian Linux9.0
OracleRest Data Services11.2.0.4
OracleRetail Xstore Payment3.3
OracleRetail Xstore Point Of Service7.1
HpXp P9000 Command View>= 8.4.0-00, <= 8.6.2-00
HpXp P9000-
NetappE-Series Santricity Management-
NetappE-Series Santricity Os Controller>= 11.0, <= 11.50.1
NetappE-Series Santricity Web Services-
NetappHci Management Node-
NetappHci Storage Node-
NetappOncommand System Manager>= 3.0, <= 3.1.3
NetappOncommand Unified Manager For 7-Mode-
NetappSantricity Cloud Connector-
NetappSnap Creator Framework-
NetappSnapcenter-
NetappSnapmanager-
NetappSolidfire-
NetappStorage Services Connector-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-7658?

CVE-2017-7658 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the ...

How severe is CVE-2017-7658?

CVE-2017-7658 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2017-7658?

Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Jetty, Debian Debian Linux, Oracle Rest Data Services, Oracle Retail Xstore Payment, Oracle Retail Xstore Point Of Service.