SUSE-SU-2023:4210-1

Advisory lineage Upstream: 5 Downstream: 0
Published: 26 Oct 2023, 08:26
Last modified:04 Feb 2026, 03:26

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Oct 2023, 08:26
Published
Vulnerability first disclosed
04 Feb 2026, 03:26
Last Modified
Vulnerability information updated

Description

Security update for jetty-minimal This update for jetty-minimal fixes the following issues: - Updated to version 9.4.53.v20231009: - CVE-2023-44487: Fixed a potential denial of service scenario via RST frame floods (bsc#1216169). - CVE-2023-36478: Fixed an integer overflow in the HTTP/2 HPACK decoder (bsc#1216162). - CVE-2023-40167: Fixed a permissive HTTP header parsing issue that could potentially lead to HTTP smuggling attacks (bsc#1215417). - CVE-2023-36479: Fixed an incorrect command execution when sending requests with certain characters in requested filenames (bsc#1215415). - CVE-2023-41900: Fixed an issue where an invalidated session would be allowed to perform a single request (bsc#1215416).

Affected Systems

  • opensusejetty-minimal&distro=openSUSE Leap 15.4

    < 9.4.53-150200.3.22.1

  • opensusejetty-minimal&distro=openSUSE Leap 15.5

    < 9.4.53-150200.3.22.1

  • susejetty-minimal&distro=SUSE Enterprise Storage 7.1

    < 9.4.53-150200.3.22.1

  • susejetty-minimal&distro=SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS

    < 9.4.53-150200.3.22.1

  • susejetty-minimal&distro=SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS

    < 9.4.53-150200.3.22.1

  • susejetty-minimal&distro=SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS

    < 9.4.53-150200.3.22.1

  • susejetty-minimal&distro=SUSE Linux Enterprise Module for Development Tools 15 SP4

    < 9.4.53-150200.3.22.1

  • susejetty-minimal&distro=SUSE Linux Enterprise Module for Development Tools 15 SP5

    < 9.4.53-150200.3.22.1

  • susejetty-minimal&distro=SUSE Linux Enterprise Server 15 SP2-LTSS

    < 9.4.53-150200.3.22.1

  • susejetty-minimal&distro=SUSE Linux Enterprise Server 15 SP3-LTSS

    < 9.4.53-150200.3.22.1

  • susejetty-minimal&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP2

    < 9.4.53-150200.3.22.1

  • susejetty-minimal&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP3

    < 9.4.53-150200.3.22.1

References (11)