CVE-2023-40167
Summary
| CVE | CVE-2023-40167 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-15 20:15:00 UTC |
| Updated | 2023-10-13 01:59:00 UTC |
| Description | Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field. This is more permissive than allowed by the RFC and other servers routinely reject such requests with 400 responses. There is no known exploit scenario, but it is conceivable that request smuggling could result if jetty is used in combination with a server that does not close the connection after sending such a 400 response. Versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1 contain a patch for this issue. There is no workaround as there is no known exploit scenario. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Jetty accepts "+" prefixed value in Content-Length · Advisory · eclipse/jetty.project · GitHub |
MISC |
github.com |
|
| [SECURITY] [DLA 3592-1] jetty9 security update |
MISC |
lists.debian.org |
|
| RFC 9110: HTTP Semantics |
MISC |
www.rfc-editor.org |
|
| Debian -- Security Information -- DSA-5507-1 jetty9 |
MISC |
www.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 20401 Oracle Database 21c Critical Patch Update - January 2024
- 242923 Red Hat Update for Satellite 6.14.2 (RHSA-2024:0797)
- 357226 Amazon Linux Security Advisory for jetty : ALAS2-2024-2460
- 379516 IBM Sterling Secure Proxy Multiple Vulnerabilities (7142038)
- 6000122 Debian Security Update for jetty9 (DLA 3592-1)
- 6000216 Debian Security Update for jetty9 (DSA 5507-1)
- 755165 SUSE Enterprise Linux Security Update for jetty-minimal (SUSE-SU-2023:4210-1)
- 995277 Java (Maven) Security Update for org.eclipse.jetty:jetty-http (GHSA-hmr7-m48g-48f6)