VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 20 hours ago

CVE-2017-7658

9.8 Critical No fix identified

Description

In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.

CWE-444

Exploitation Status

No public exploit

Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 8 years.

CVSS E:U

  • CISA KEV not listed
  • CISA Vulnrichment no assessment published
  • Indexed PoC none indexed
  • EPSS 19% chance in 30 days A model prediction, not an observation. Higher than 97% of all scored CVEs.

Waratek Defense Posture

No fix identified

In RASP's scope, but nothing published names a fix and nothing published shows an exploit. Neither of the two things VRT can act on exists, which is a claim about the available evidence, not about the vulnerability.

  • Protection none
  • Action not-needed
  • Review human manual-review
  • Record active
Decided by manual classification : Manual classification of this CVE in the legacy dataset
Finding Manual classification assigned status: NO-FIX-IDENTIFIED

CVSS

9.8 CRITICAL v3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 2 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H NVD Primary published
CVSS 2.0 7.5 no band published AV:N/AC:L/Au:N/C:P/I:P/A:P NVD Primary

Affected Software & Releases

🏛️ Oracle CPU Advisories & Products

AdvisoryTypeQuarterProducts Oracle named in risk matrix
Oracle Critical Patch Update October 2020 CPU 2020-Q4 Oracle REST Data Services / General (Eclipse Jetty) (11.2.0.4, 12.1.0.2, 12.2.0.1, 18c)
Oracle Critical Patch Update January 2019 CPU 2019-Q1 Oracle Retail Applications / Security (Jetty) (3.3)

Indexed Oracle Components & Versions

FamilyComponentOracle's version cell (verbatim)Indexed as
Oracle REST Data Services General (Eclipse Jetty) 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c 11.2.0.4 · 12.1.0.2 · 12.2.0.1 · 18
Oracle Retail Applications Security (Jetty) 3.3 3.3

☕ Maven Library Packages

Artifact coordinates and fix boundaries from OSV.dev
Package CoordinateIntroducedFixedLast affected
org.eclipse.jetty:jetty-server 0 9.2.25.v20180606 unbounded
org.eclipse.jetty:jetty-server 9.3.0 9.3.24.v20180605 unbounded
org.eclipse.jetty:jetty-server 9.4.0 9.4.11.v20180605 unbounded

🖥️ Product CPEs & Version Ranges

20 product(s) over 30 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd debian debian linux generic 9.0
nvd eclipse jetty generic ≤ 9.2.26 · ≥ 9.3.0 and < 9.3.24 · ≥ 9.4.0 and < 9.4.11
nvd hp xp p9000 command view generic ≥ 8.4.0.0 and ≤ 8.6.2.0
nvd netapp e-series santricity management generic any version
nvd netapp e-series santricity os controller generic ≥ 11.0 and ≤ 11.50.1
nvd netapp e-series santricity web services generic any version
nvd netapp hci management node generic any version
nvd netapp hci storage node generic any version
nvd netapp oncommand system manager generic ≥ 3.0 and ≤ 3.1.3
nvd netapp oncommand unified manager for 7-mode generic any version
nvd netapp santricity cloud connector generic any version
nvd netapp snap creator framework generic any version
nvd netapp snapcenter generic any version
nvd netapp snapmanager generic any version
nvd netapp solidfire generic any version
nvd netapp storage services connector generic any version
nvd oracle rest data services generic 11.2.0.4 · 12.1.0.2 · 12.2.0.1 · 18c
nvd oracle retail xstore payment generic 3.3
nvd oracle retail xstore point of service generic 7.1 · 15.0 · 16.0 · 17.0
osv org.eclipse.jetty jetty-server generic < 9.2.25.99999 · ≥ 9.3.0 and < 9.3.24.99999 · ≥ 9.4.0 and < 9.4.11.99999

Manual classification context

A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.

## Manual Classification Context **Labels:** SECURITY (JETTY), HTTP, GENERAL (ECLIPSE JETTY), NO AUTH REMOTE EXPLOIT **Products:** ORACLE RETAIL APPLICATIONS, JETTY, ORACLE REST DATA SERVICES, ORACLE RETAIL XSTORE PAYMENT

References

URLTags
https://bugs.eclipse.org/bugs/show_bug.cgi?id=535669 WEB
https://github.com/advisories/GHSA-6x9x-8qw9-9pp6 ADVISORY
https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272@%3Cissues.activemq.apache.org%3E WEB
https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E WEB
https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E WEB
https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E WEB
https://lists.apache.org/thread.html/r41af10c4adec8d34a969abeb07fd0d6ad0c86768b751464f1cdd23e8@%3Ccommits.druid.apache.org%3E WEB
https://lists.apache.org/thread.html/r9159c9e7ec9eac1613da2dbaddbc15691a13d4dbb2c8be974f42e6ae@%3Ccommits.druid.apache.org%3E WEB
https://lists.apache.org/thread.html/ra6f956ed4ec2855583b2d0c8b4802b450f593d37b77509b48cd5d574@%3Ccommits.druid.apache.org%3E WEB
https://security.netapp.com/advisory/ntap-20181014-0001 WEB

Timeline

Published 2018-06-26 Last modified 2026-06-17
Published2018-06-26By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.