Improper Input Validation Affecting org.eclipse.jetty:jetty-http package, versions [,9.4.47) [10.0.0-alpha0,10.0.10) [11.0.0-alpha0,11.0.10)


0.0
low

Snyk CVSS

    Attack Complexity Low
    Privileges Required High

    Threat Intelligence

    EPSS 0.09% (36th percentile)
Expand this section
NVD
2.7 low
Expand this section
Red Hat
2.7 low

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JAVA-ORGECLIPSEJETTY-2945452
  • published 8 Jul 2022
  • disclosed 7 Jul 2022
  • credit Unknown

How to fix?

Upgrade org.eclipse.jetty:jetty-http to version 9.4.47, 10.0.10, 11.0.10 or higher.

Overview

org.eclipse.jetty:jetty-http is an is a http module for jetty server.

Affected versions of this package are vulnerable to Improper Input Validation due to improper URI paring in the HttpURI class.