Description
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3079-1 | jetty9 security update |
Debian DSA |
DSA-5198-1 | jetty9 security update |
EUVD |
EUVD-2022-6317 | In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario. |
Github GHSA |
GHSA-cj7v-27pg-wf7q | Jetty invalid URI parsing may produce invalid HttpURI.authority |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Eclipse
Subscribe
Jetty
Subscribe
Netapp
Subscribe
Element Plug-in For Vcenter Server
Subscribe
Hci Compute Node
Subscribe
Management Services For Element Software And Netapp Hci
Subscribe
Snapcenter
Subscribe
Solidfire \& Hci Storage Node
Subscribe
Redhat
Subscribe
Amq Broker
Subscribe
Amq Streams
Subscribe
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-03T00:24:44.138Z
Reserved: 2022-06-09T00:00:00.000Z
Link: CVE-2022-2047
No data.
Status : Modified
Published: 2022-07-07T21:15:10.093
Modified: 2024-11-21T07:00:13.840
Link: CVE-2022-2047
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA