CVE-2022-2047
Summary
| CVE | CVE-2022-2047 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-07 21:15:00 UTC |
| Updated | 2022-10-25 19:10:00 UTC |
| Description | In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Invalid URI parsing may produce invalid HttpURI.authority · Advisory · eclipse/jetty.project · GitHub |
CONFIRM |
github.com |
|
| August 2022 Eclipse Jetty Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| Debian -- Security Information -- DSA-5198-1 jetty9 |
DEBIAN |
www.debian.org |
|
| [SECURITY] [DLA 3079-1] jetty9 security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180910 Debian Security Update for jetty9 (DSA 5198-1)
- 180954 Debian Security Update for jetty9 (DLA 3079-1)
- 182741 Debian Security Update for jetty9 (CVE-2022-2047)
- 20270 Oracle Database 21c Critical Patch Update - October 2022
- 20271 Oracle Database 19c Critical Patch Update - October 2022
- 20272 Oracle Database 19c Critical OJVM Patch Update - October 2022