← All CVEs

CVE-2017-7657

critical · 9.8

In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.

9.8
CVSS
14.9%
EPSS (exploit prob.)
97th
EPSS percentile
2018-06-26
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-444CWE-190

Affected products

VendorProductAffected versions
eclipsejetty<= 9.2.26
eclipsejetty>= 9.3.0, < 9.3.24
eclipsejetty>= 9.4.0, < 9.4.11
debiandebian_linux9.0
netappe-series_santricity_managementall versions
netappe-series_santricity_os_controller>= 11.0, <= 11.50.1
netappe-series_santricity_web_servicesall versions
netappelement_softwareall versions
netappelement_software_management_nodeall versions
netapphci_storage_nodesall versions
netapponcommand_system_manager3.x
netapponcommand_unified_manager< 5.2.4
netappsantricity_cloud_connectorall versions
netappsnap_creator_framework< 4.3.3
netappsnapcenter< 4.1p3
netappsnapmanager< 3.4.2
netappsnapmanager< 3.4.2
hpxp_p9000_command_view>= 8.4.0-00, < 8.6.2-00
hpxp_p9000all versions
oraclerest_data_services11.2.0.4
oraclerest_data_services12.1.0.2
oraclerest_data_services12.2.0.1
oraclerest_data_services18c
oracleretail_xstore_point_of_service7.1
oracleretail_xstore_point_of_service15.0
oracleretail_xstore_point_of_service16.0
oracleretail_xstore_point_of_service17.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-7657