5.3

CVE-2023-40167

Jetty accepts "+" prefixed value in Content-Length

Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field.  This is more permissive than allowed by the RFC and other servers routinely reject such requests with 400 responses.  There is no known exploit scenario, but it is conceivable that request smuggling could result if jetty is used in combination with a server that does not close the connection after sending such a 400 response. Versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1 contain a patch for this issue. There is no workaround as there is no known exploit scenario.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eclipse ≫ Jetty Version >= 9.0.0 < 9.4.52
Eclipse ≫ Jetty Version >= 10.0.0 < 10.0.16
Eclipse ≫ Jetty Version >= 11.0.0 < 11.0.16
Eclipse ≫ Jetty Version 12.0.0 Update -
Eclipse ≫ Jetty Version 12.0.0 Update beta0
Eclipse ≫ Jetty Version 12.0.0 Update beta1
Eclipse ≫ Jetty Version 12.0.0 Update beta2
Eclipse ≫ Jetty Version 12.0.0 Update beta3
Eclipse ≫ Jetty Version 12.0.0 Update beta4
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Debian ≫ Debian Linux Version 12.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.07% 0.604
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
security-advisories@github.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-130 Improper Handling of Length Parameter Inconsistency

The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.

https://lists.debian.org/debian-lts-announce/2023/09/msg00039.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2023/dsa-5507
Third Party Advisory
https://github.com/eclipse/jetty.project/security/advisories/GHSA-hmr7-m48g-48f6
Vendor Advisory
https://www.rfc-editor.org/rfc/rfc9110#section-8.6
Technical Description