VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 20 hours ago

CVE-2017-7657

9.8 Critical No fix identified

Description

In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.

CWE-444CWE-190 · Integer overflow

Exploitation Status

No public exploit

Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 8 years.

CVSS E:U

  • CISA KEV not listed
  • CISA Vulnrichment no assessment published
  • Indexed PoC none indexed
  • EPSS 15% chance in 30 days A model prediction, not an observation. Higher than 96% of all scored CVEs.

Waratek Defense Posture

No fix identified

In RASP's scope, but nothing published names a fix and nothing published shows an exploit. Neither of the two things VRT can act on exists, which is a claim about the available evidence, not about the vulnerability.

  • Protection none
  • Action not-needed
  • Review human manual-review
  • Record active
Decided by manual classification : Manual classification of this CVE in the legacy dataset
Finding Manual classification assigned status: NO-FIX-IDENTIFIED

CVSS

9.8 CRITICAL v3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 2 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H NVD Primary published
CVSS 2.0 7.5 no band published AV:N/AC:L/Au:N/C:P/I:P/A:P NVD Primary

Affected Software & Releases

☕ Maven Library Packages

Artifact coordinates and fix boundaries from OSV.dev
Package CoordinateIntroducedFixedLast affected
org.eclipse.jetty:jetty-server 0 9.2.25.v20180606 unbounded
org.eclipse.jetty:jetty-server 9.3.0 9.3.24.v20180605 unbounded

🖥️ Product CPEs & Version Ranges

18 product(s) over 27 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd debian debian linux generic 9.0
nvd eclipse jetty generic ≤ 9.2.26 · ≥ 9.3.0 and < 9.3.24 · ≥ 9.4.0 and < 9.4.11
nvd hp xp p9000 command view generic ≥ 8.4.0.0 and < 8.6.2.0
nvd netapp e-series santricity management generic any version
nvd netapp e-series santricity os controller generic ≥ 11.0 and ≤ 11.50.1
nvd netapp e-series santricity web services generic any version
nvd netapp element software generic any version
nvd netapp element software management node generic any version
nvd netapp hci storage nodes generic any version
nvd netapp oncommand system manager generic 3.x
nvd netapp oncommand unified manager generic < 5.2.4
nvd netapp santricity cloud connector generic any version
nvd netapp snap creator framework generic < 4.3.3
nvd netapp snapcenter generic < 4.1.3
nvd netapp snapmanager generic < 3.4.2
nvd oracle rest data services generic 11.2.0.4 · 12.1.0.2 · 12.2.0.1 · 18c
nvd oracle retail xstore point of service generic 7.1 · 15.0 · 16.0 · 17.0
osv org.eclipse.jetty jetty-server generic < 9.2.25.99999 · ≥ 9.3.0 and < 9.3.24.99999

References

URLTags
https://access.redhat.com/errata/RHSA-2019:0910 WEB
https://bugs.eclipse.org/bugs/show_bug.cgi?id=535668 WEB
https://github.com/advisories/GHSA-vgg8-72f2-qm23 ADVISORY
https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272@%3Cissues.activemq.apache.org%3E WEB
https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E WEB
https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E WEB
https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E WEB
https://lists.apache.org/thread.html/r41af10c4adec8d34a969abeb07fd0d6ad0c86768b751464f1cdd23e8@%3Ccommits.druid.apache.org%3E WEB
https://lists.apache.org/thread.html/r9159c9e7ec9eac1613da2dbaddbc15691a13d4dbb2c8be974f42e6ae@%3Ccommits.druid.apache.org%3E WEB
https://lists.apache.org/thread.html/ra6f956ed4ec2855583b2d0c8b4802b450f593d37b77509b48cd5d574@%3Ccommits.druid.apache.org%3E WEB

Timeline

Published 2018-06-26 Last modified 2026-06-17
Published2018-06-26By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.