In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
28
Affected Products
34
References
eclipse / jetty
| - |
| debian | debian_linux | - | - |
| oracle | rest_data_services | - | - |
| oracle | rest_data_services | - | - |
| oracle | rest_data_services | - | - |
| oracle | rest_data_services | - | - |
| oracle | retail_xstore_payment | - | - |
| oracle | retail_xstore_point_of_service | - | - |
| oracle | retail_xstore_point_of_service | - | - |
| oracle | retail_xstore_point_of_service | - | - |
| oracle | retail_xstore_point_of_service | - | - |
| hp | xp_p9000_command_view | 8.4.0-00 - 8.6.2-00 | - |
| netapp | e-series_santricity_management | - | - |
| netapp | e-series_santricity_os_controller | 11.0 - 11.50.1 | - |
| netapp | e-series_santricity_web_services | - | - |
| netapp | hci_management_node | - | - |
| netapp | hci_storage_node | - | - |
| netapp | oncommand_system_manager | 3.0 - 3.1.3 | - |
| netapp | oncommand_unified_manager_for_7-mode | - | - |
| netapp | santricity_cloud_connector | - | - |
| netapp | snap_creator_framework | - | - |
| netapp | snapcenter | - | - |
| netapp | snapmanager | - | - |
| netapp | snapmanager | - | - |
| netapp | solidfire | - | - |
| netapp | storage_services_connector | - | - |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability
Impact