CVE-2017-7658In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.
CWE-444
No public exploit
Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 8 years.
CVSS E:U
In RASP's scope, but nothing published names a fix and nothing published shows an exploit. Neither of the two things VRT can act on exists, which is a claim about the available evidence, not about the vulnerability.
| Decided by | manual classification : Manual classification of this CVE in the legacy dataset |
|---|---|
| Finding | Manual classification assigned status: NO-FIX-IDENTIFIED |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
2 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
NVD | Primary | published |
| CVSS 2.0 | 7.5 | no band published | AV:N/AC:L/Au:N/C:P/I:P/A:P |
NVD | Primary |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update October 2020 ↗ | CPU | 2020-Q4 | Oracle REST Data Services / General (Eclipse Jetty) (11.2.0.4, 12.1.0.2, 12.2.0.1, 18c) |
| Oracle Critical Patch Update January 2019 ↗ | CPU | 2019-Q1 | Oracle Retail Applications / Security (Jetty) (3.3) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle REST Data Services | General (Eclipse Jetty) | 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c | 11.2.0.4 · 12.1.0.2 · 12.2.0.1 · 18 |
| Oracle Retail Applications | Security (Jetty) | 3.3 | 3.3 |
| Package Coordinate | Introduced | Fixed | Last affected |
|---|---|---|---|
org.eclipse.jetty:jetty-server |
0 | 9.2.25.v20180606 |
unbounded |
org.eclipse.jetty:jetty-server |
9.3.0 | 9.3.24.v20180605 |
unbounded |
org.eclipse.jetty:jetty-server |
9.4.0 | 9.4.11.v20180605 |
unbounded |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | debian | debian linux | generic | 9.0 |
| nvd | eclipse | jetty | generic | ≤ 9.2.26 · ≥ 9.3.0 and < 9.3.24 · ≥ 9.4.0 and < 9.4.11 |
| nvd | hp | xp p9000 command view | generic | ≥ 8.4.0.0 and ≤ 8.6.2.0 |
| nvd | netapp | e-series santricity management | generic | any version |
| nvd | netapp | e-series santricity os controller | generic | ≥ 11.0 and ≤ 11.50.1 |
| nvd | netapp | e-series santricity web services | generic | any version |
| nvd | netapp | hci management node | generic | any version |
| nvd | netapp | hci storage node | generic | any version |
| nvd | netapp | oncommand system manager | generic | ≥ 3.0 and ≤ 3.1.3 |
| nvd | netapp | oncommand unified manager for 7-mode | generic | any version |
| nvd | netapp | santricity cloud connector | generic | any version |
| nvd | netapp | snap creator framework | generic | any version |
| nvd | netapp | snapcenter | generic | any version |
| nvd | netapp | snapmanager | generic | any version |
| nvd | netapp | solidfire | generic | any version |
| nvd | netapp | storage services connector | generic | any version |
| nvd | oracle | rest data services | generic | 11.2.0.4 · 12.1.0.2 · 12.2.0.1 · 18c |
| nvd | oracle | retail xstore payment | generic | 3.3 |
| nvd | oracle | retail xstore point of service | generic | 7.1 · 15.0 · 16.0 · 17.0 |
| osv | org.eclipse.jetty | jetty-server | generic | < 9.2.25.99999 · ≥ 9.3.0 and < 9.3.24.99999 · ≥ 9.4.0 and < 9.4.11.99999 |
A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.
## Manual Classification Context **Labels:** SECURITY (JETTY), HTTP, GENERAL (ECLIPSE JETTY), NO AUTH REMOTE EXPLOIT **Products:** ORACLE RETAIL APPLICATIONS, JETTY, ORACLE REST DATA SERVICES, ORACLE RETAIL XSTORE PAYMENT
| Published | 2018-06-26 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |