CVE-2022-2047
Vulnerability Summary
Timeline
Description
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
CVSS Metrics
- v3.1•LOW•Score: 2.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
- v2.0•MEDIUM•Score: 4AV:N/AC:L/Au:S/C:N/I:P/A:N
EPSS Trends
Current EPSS score: 0.40%• Percentile: 61%
Techniques & Countermeasures
- CWE-20•Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Affected Systems
- debian•debian_linux
10.0 | 11.0
- eclipse•jetty
< 9.4.46 | ≥ 10.0.0, < 10.0.9 | ≥ 11.0.0, ≤ 11.0.9
- org.eclipse.jetty•jetty-http
< 9.4.47 | ≥ 10.0.0, < 10.0.10 | ≥ 11.0.0, < 11.0.10
- netapp•element_plug-in_for_vcenter_server
na
- netapp•hci_compute_node_firmware
na
- netapp•management_services_for_element_software_and_netapp_hci
na
- netapp•snapcenter
na
- netapp•solidfire_\&_hci_storage_node
na
- the eclipse foundation•eclipse jetty
≥ 9.4.0, < unspecified | ≥ unspecified, ≤ 9.4.46 | ≥ 10.0.0, < unspecified | ≥ unspecified, ≤ 10.0.9 | ≥ 11.0.0, < unspecified | ≥ unspecified, ≤ 11.0.9
References (7)
- https://github.com/eclipse/jetty.project/security/advisories/GHSA-cj7v-27pg-wf7q
- https://www.debian.org/security/2022/dsa-5198
- https://lists.debian.org/debian-lts-announce/2022/08/msg00011.html
- https://security.netapp.com/advisory/ntap-20220901-0006/
- https://nvd.nist.gov/vuln/detail/CVE-2022-2047
- https://github.com/eclipse/jetty.project
- https://security.netapp.com/advisory/ntap-20220901-0006