CVE-2017-7657In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.
CWE-444CWE-190 · Integer overflow
No public exploit
Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 8 years.
CVSS E:U
In RASP's scope, but nothing published names a fix and nothing published shows an exploit. Neither of the two things VRT can act on exists, which is a claim about the available evidence, not about the vulnerability.
| Decided by | manual classification : Manual classification of this CVE in the legacy dataset |
|---|---|
| Finding | Manual classification assigned status: NO-FIX-IDENTIFIED |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
2 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
NVD | Primary | published |
| CVSS 2.0 | 7.5 | no band published | AV:N/AC:L/Au:N/C:P/I:P/A:P |
NVD | Primary |
| Package Coordinate | Introduced | Fixed | Last affected |
|---|---|---|---|
org.eclipse.jetty:jetty-server |
0 | 9.2.25.v20180606 |
unbounded |
org.eclipse.jetty:jetty-server |
9.3.0 | 9.3.24.v20180605 |
unbounded |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | debian | debian linux | generic | 9.0 |
| nvd | eclipse | jetty | generic | ≤ 9.2.26 · ≥ 9.3.0 and < 9.3.24 · ≥ 9.4.0 and < 9.4.11 |
| nvd | hp | xp p9000 command view | generic | ≥ 8.4.0.0 and < 8.6.2.0 |
| nvd | netapp | e-series santricity management | generic | any version |
| nvd | netapp | e-series santricity os controller | generic | ≥ 11.0 and ≤ 11.50.1 |
| nvd | netapp | e-series santricity web services | generic | any version |
| nvd | netapp | element software | generic | any version |
| nvd | netapp | element software management node | generic | any version |
| nvd | netapp | hci storage nodes | generic | any version |
| nvd | netapp | oncommand system manager | generic | 3.x |
| nvd | netapp | oncommand unified manager | generic | < 5.2.4 |
| nvd | netapp | santricity cloud connector | generic | any version |
| nvd | netapp | snap creator framework | generic | < 4.3.3 |
| nvd | netapp | snapcenter | generic | < 4.1.3 |
| nvd | netapp | snapmanager | generic | < 3.4.2 |
| nvd | oracle | rest data services | generic | 11.2.0.4 · 12.1.0.2 · 12.2.0.1 · 18c |
| nvd | oracle | retail xstore point of service | generic | 7.1 · 15.0 · 16.0 · 17.0 |
| osv | org.eclipse.jetty | jetty-server | generic | < 9.2.25.99999 · ≥ 9.3.0 and < 9.3.24.99999 |
| Published | 2018-06-26 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |