Improper Input Validation Affecting org.eclipse.jetty:jetty-http package, versions [,9.4.47) [10.0.0-alpha0,10.0.10) [11.0.0-alpha0,11.0.10)
Threat Intelligence
EPSS
0.17% (56th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGECLIPSEJETTY-2945452
- published 8 Jul 2022
- disclosed 7 Jul 2022
- credit Unknown
How to fix?
Upgrade org.eclipse.jetty:jetty-http
to version 9.4.47, 10.0.10, 11.0.10 or higher.
Overview
org.eclipse.jetty:jetty-http is an is a http module for jetty server.
Affected versions of this package are vulnerable to Improper Input Validation due to improper URI paring in the HttpURI
class.
CVSS Scores
version 3.1