CVE-2017-7656
Jetty vulnerable to cache poisoning due to inconsistent HTTP request handling (HTTP Request Smuggling)
Description
Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), contain an HTTP Request Smuggling Vulnerability that can result in cache poisoning.
Base CVSS
7.5
EPSS Score
6.38%
Introduced Version
7.0.0.M0
Fix Available
9.2.25.v20180606,9.3.24.v20180605,9.4.11.v20180605
Available Patches
Package
CVEs Fixed
Lines of Code Changed