{"id":"GHSA-vgg8-72f2-qm23","summary":"Critical severity vulnerability that affects org.eclipse.jetty:jetty-server","details":"In Eclipse Jetty, versions 9.2.x and older, 9.3.x, transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.","aliases":["CVE-2017-7657"],"modified":"2024-02-17T05:35:13.647140Z","published":"2018-10-19T16:15:34Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:57:40Z","nvd_published_at":"2018-06-26T16:29:00Z","cwe_ids":["CWE-190","CWE-444"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7657"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:0910"},{"type":"WEB","url":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=535668"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vgg8-72f2-qm23"},{"type":"WEB","url":"https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272@%3Cissues.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r41af10c4adec8d34a969abeb07fd0d6ad0c86768b751464f1cdd23e8@%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r9159c9e7ec9eac1613da2dbaddbc15691a13d4dbb2c8be974f42e6ae@%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ra6f956ed4ec2855583b2d0c8b4802b450f593d37b77509b48cd5d574@%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20181014-0001"},{"type":"WEB","url":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03953en_us"},{"type":"WEB","url":"https://www.debian.org/security/2018/dsa-4278"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"WEB","url":"https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"},{"type":"WEB","url":"http://www.securitytracker.com/id/1041194"}],"affected":[{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.2.25.v20180606"}]}],"versions":["7.0.0.M0","7.0.0.M1","7.0.0.M2","7.0.0.M3","7.0.0.M4","7.0.0.RC0","7.0.0.RC1","7.0.0.RC2","7.0.0.RC3","7.0.0.RC4","7.0.0.RC5","7.0.0.RC6","7.0.0.v20091005","7.0.1.v20091125","7.0.2.RC0","7.0.2.v20100331","7.1.0.RC0","7.1.0.RC1","7.1.0.v20100505","7.1.1.v20100517","7.1.2.v20100523","7.1.3.v20100526","7.1.4.v20100610","7.1.5.v20100705","7.1.6.v20100715","7.2.0.RC0","7.2.0.v20101020","7.2.1.v20101111","7.2.2.v20101205","7.3.0.v20110203","7.3.1.v20110307","7.4.0.RC0","7.4.0.v20110414","7.4.1.v20110513","7.4.2.v20110526","7.4.3.v20110701","7.4.4.v20110707","7.4.5.v20110725","7.5.0.RC0","7.5.0.RC1","7.5.0.RC2","7.5.0.v20110901","7.5.1.v20110908","7.5.2.v20111006","7.5.3.v20111011","7.5.4.v20111024","7.6.0.RC0","7.6.0.RC1","7.6.0.RC2","7.6.0.RC3","7.6.0.RC4","7.6.0.RC5","7.6.0.v20120127","7.6.1.v20120215","7.6.10.v20130312","7.6.11.v20130520","7.6.12.v20130726","7.6.13.v20130916","7.6.14.v20131031","7.6.15.v20140411","7.6.16.v20140903","7.6.17.v20150415","7.6.18.v20150929","7.6.19.v20160209","7.6.2.v20120308","7.6.20.v20160902","7.6.21.v20160908","7.6.3.v20120416","7.6.4.v20120524","7.6.5.v20120716","7.6.6.v20120903","7.6.7.v20120910","7.6.8.v20121106","7.6.9.v20130131","8.0.0.M0","8.0.0.M1","8.0.0.M2","8.0.0.M3","8.0.0.RC0","8.0.0.v20110901","8.0.1.v20110908","8.0.2.v20111006","8.0.3.v20111011","8.0.4.v20111024","8.1.0.RC0","8.1.0.RC1","8.1.0.RC2","8.1.0.RC4","8.1.0.RC5","8.1.0.v20120127","8.1.1.v20120215","8.1.10.v20130312","8.1.11.v20130520","8.1.12.v20130726","8.1.13.v20130916","8.1.14.v20131031","8.1.15.v20140411","8.1.16.v20140903","8.1.17.v20150415","8.1.18.v20150929","8.1.19.v20160209","8.1.2.v20120308","8.1.20.v20160902","8.1.21.v20160908","8.1.22.v20160922","8.1.3.v20120416","8.1.4.v20120524","8.1.5.v20120716","8.1.6.v20120903","8.1.7.v20120910","8.1.8.v20121106","8.1.9.v20130131","8.2.0.v20160908","9.0.0.M0","9.0.0.M1","9.0.0.M2","9.0.0.M3","9.0.0.M4","9.0.0.M5","9.0.0.RC0","9.0.0.RC1","9.0.0.RC2","9.0.0.v20130308","9.0.1.v20130408","9.0.2.v20130417","9.0.3.v20130506","9.0.4.v20130625","9.0.5.v20130815","9.0.6.v20130930","9.0.7.v20131107","9.1.0.M0","9.1.0.RC0","9.1.0.RC1","9.1.0.RC2","9.1.0.v20131115","9.1.1.v20140108","9.1.2.v20140210","9.1.3.v20140225","9.1.4.v20140401","9.1.5.v20140505","9.1.6.v20160112","9.2.0.M0","9.2.0.M1","9.2.0.RC0","9.2.0.v20140526","9.2.1.v20140609","9.2.10.v20150310","9.2.11.M0","9.2.11.v20150529","9.2.12.M0","9.2.12.v20150709","9.2.13.v20150730","9.2.14.v20151106","9.2.15.v20160210","9.2.16.v20160414","9.2.17.v20160517","9.2.18.v20160721","9.2.19.v20160908","9.2.2.v20140723","9.2.20.v20161216","9.2.21.v20170120","9.2.22.v20170606","9.2.23.v20171218","9.2.24.v20180105","9.2.3.v20140905","9.2.4.v20141103","9.2.5.v20141112","9.2.6.v20141205","9.2.7.v20150116","9.2.8.v20150217","9.2.9.v20150224"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-vgg8-72f2-qm23/GHSA-vgg8-72f2-qm23.json","last_known_affected_version_range":"\u003c= 9.2.25.v20180105"}},{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.3.0"},{"fixed":"9.3.24.v20180605"}]}],"versions":["9.3.0.v20150612","9.3.1.v20150714","9.3.10.M0","9.3.10.v20160621","9.3.11.M0","9.3.11.v20160721","9.3.12.v20160915","9.3.13.M0","9.3.13.v20161014","9.3.14.v20161028","9.3.15.v20161220","9.3.16.v20170120","9.3.17.RC0","9.3.17.v20170317","9.3.18.v20170406","9.3.19.v20170502","9.3.2.v20150730","9.3.20.v20170531","9.3.21.M0","9.3.21.RC0","9.3.21.v20170918","9.3.22.v20171030","9.3.23.v20180228","9.3.3.v20150827","9.3.4.RC0","9.3.4.RC1","9.3.4.v20151007","9.3.5.v20151012","9.3.6.v20151106","9.3.7.RC0","9.3.7.RC1","9.3.7.v20160115","9.3.8.RC0","9.3.8.v20160314","9.3.9.M0","9.3.9.M1","9.3.9.v20160517"],"database_specific":{"last_known_affected_version_range":"\u003c= 9.3.23.v20180228","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-vgg8-72f2-qm23/GHSA-vgg8-72f2-qm23.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}