Логотип exploitDog
bind:CVE-2024-6763
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-6763

Количество 8

Количество 8

ubuntu логотип

CVE-2024-6763

около 1 года назад

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2024-6763

около 1 года назад

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2024-6763

около 1 года назад

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2024-6763

около 1 года назад

Eclipse Jetty is a lightweight, highly scalable, Java-based web server ...

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-qh8g-58pp-2wxh

около 1 года назад

Eclipse Jetty URI parsing of invalid authority

CVSS3: 3.7
EPSS: Низкий
fstec логотип

BDU:2024-10117

около 1 года назад

Уязвимость класса HttpURI контейнера сервлетов Eclipse Jetty, позволяющая нарушителю осуществить SSRF-атаку

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01738-1

7 месяцев назад

Security update for jetty-minimal

EPSS: Низкий
redos логотип

ROS-20250630-04

6 месяцев назад

Множественные уязвимости jetty

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-6763

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.

CVSS3: 3.7
1%
Низкий
около 1 года назад
redhat логотип
CVE-2024-6763

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.

CVSS3: 3.7
1%
Низкий
около 1 года назад
nvd логотип
CVE-2024-6763

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.

CVSS3: 3.7
1%
Низкий
около 1 года назад
debian логотип
CVE-2024-6763

Eclipse Jetty is a lightweight, highly scalable, Java-based web server ...

CVSS3: 3.7
1%
Низкий
около 1 года назад
github логотип
GHSA-qh8g-58pp-2wxh

Eclipse Jetty URI parsing of invalid authority

CVSS3: 3.7
1%
Низкий
около 1 года назад
fstec логотип
BDU:2024-10117

Уязвимость класса HttpURI контейнера сервлетов Eclipse Jetty, позволяющая нарушителю осуществить SSRF-атаку

CVSS3: 5.3
1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01738-1

Security update for jetty-minimal

7 месяцев назад
redos логотип
ROS-20250630-04

Множественные уязвимости jetty

CVSS3: 7.2
6 месяцев назад

Уязвимостей на страницу