Логотип exploitDog
bind: "CVE-2024-6763"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-6763"

Количество 8

Количество 8

ubuntu логотип

CVE-2024-6763

11 месяцев назад

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2024-6763

11 месяцев назад

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2024-6763

11 месяцев назад

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2024-6763

11 месяцев назад

Eclipse Jetty is a lightweight, highly scalable, Java-based web server ...

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-qh8g-58pp-2wxh

11 месяцев назад

Eclipse Jetty URI parsing of invalid authority

CVSS3: 3.7
EPSS: Низкий
fstec логотип

BDU:2024-10117

11 месяцев назад

Уязвимость класса HttpURI контейнера сервлетов Eclipse Jetty, позволяющая нарушителю осуществить SSRF-атаку

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01738-1

4 месяца назад

Security update for jetty-minimal

EPSS: Низкий
redos логотип

ROS-20250630-04

2 месяца назад

Множественные уязвимости jetty

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-6763

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.

CVSS3: 3.7
0%
Низкий
11 месяцев назад
redhat логотип
CVE-2024-6763

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.

CVSS3: 3.7
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2024-6763

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.

CVSS3: 3.7
0%
Низкий
11 месяцев назад
debian логотип
CVE-2024-6763

Eclipse Jetty is a lightweight, highly scalable, Java-based web server ...

CVSS3: 3.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-qh8g-58pp-2wxh

Eclipse Jetty URI parsing of invalid authority

CVSS3: 3.7
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2024-10117

Уязвимость класса HttpURI контейнера сервлетов Eclipse Jetty, позволяющая нарушителю осуществить SSRF-атаку

CVSS3: 5.3
0%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:01738-1

Security update for jetty-minimal

4 месяца назад
redos логотип
ROS-20250630-04

Множественные уязвимости jetty

CVSS3: 7.2
2 месяца назад

Уязвимостей на страницу