In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
References
| Link | Resource |
|---|---|
| https://github.com/eclipse/jetty.project/security/advisories/GHSA-cj7v-27pg-wf7q | Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-07-07 21:15
Updated : 2022-07-15 15:33
NVD link : CVE-2022-2047
Mitre link : CVE-2022-2047
JSON object : View
Products Affected
eclipse
- jetty
CWE
CWE-20
Improper Input Validation
