CVE-2024-6763
LowVulnerability Description
Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.
The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI
differs from the common browsers in how it handles a URI that would be
considered invalid if fully validated against the RRC. Specifically HttpURI
and the browser may differ on the value of the host extracted from an
invalid URI and thus a combination of Jetty and a vulnerable browser may
be vulnerable to a open redirect attack or to a SSRF attack if the URI
is used after passing validation checks.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Known Affected Software
205 configuration(s) from 1 vendor(s)
cpe:2.3:a:eclipse:jetty:9.3.4:20151005:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.6:20151106:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.2:20120302:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.30:20200611:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.8:20171121:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.37:20210219:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.7:20160115:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.2:20140723:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.1.0:20131115:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.2:20150730:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.7:20170914:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.3:20150825:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.1.4:20090609:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.4.0:20110414:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.0.7:20131031:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.1.1:20140108:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.0.3:20111011:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.11:20160721:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.5:20151012:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.29:20200521:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.3:20120413:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.26:20200117:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.1.3:20100526:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.5.4:20111024:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.11:20180605:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.17:20190418:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.16:20140903:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.19:20160908:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.12:20180830:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.55:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.0.0:20130308:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.10:20160621:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.0.1:20130408:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.10:20130312:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.47:20220610:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.33:20201020:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.5.1:20110907:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.21:20190926:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.9:20180320:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.23:20180228:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.12:20130725:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.4.1:20110512:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.8:20160311:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.8:20121106:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.24:20180605:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.27:20200227:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.3:20170317:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.21:20160908:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.40:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.14:20181114:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.4.4:20110707:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.0:maintenance0:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.6:20141203:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.18:20150929:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.9:20160517:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.0.5:20130813:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.23:20171218:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.6:20120903:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.17:20170317:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.17:20150415:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.2.0:20160908:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.0.0:20110901:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.1.0:20100505:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.22:20171030:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.21:20170918:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.53:20231009:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.24:20191120:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.1:20140609:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.19:20190610:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.2:20120302:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.3:20120413:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.13:20150730:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.43:20210629:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.15:20190215:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.1.2:20100521:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.42:20210604:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.9:20130131:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.21:20170120:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.1.5:20100705:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.41:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.10:20180503:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.20:20160902:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.18:20150929:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.0.2:20100331:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.0.1:20110907:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.6:20120903:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.25:20180904:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.0.3:20130506:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.4:20170410:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.0:20161207:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.20:20160902:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.38:20210224:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.20:20190813:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.3:20140905:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.11:20130520:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.22:20170606:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.13:20130910:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.8:20150217:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.1:20150714:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.0:20120125:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.52:20230823:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.19:20160209:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.13:20130910:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.13:20161014:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.48:20220622:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.18:20190429:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.12:20150709:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.10:20130312:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.1.2:20140210:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.12:20130726:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.14:20161028:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.0.2:20111006:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.23:20191118:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.18:20170406:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.2:20170220:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.5.0:20110901:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.0.4:20130621:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.22:20160922:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.28:20190418:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.16:20140903:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.8:20121106:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.14:20131031:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.0.2:20130417:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.0.4:20111024:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.24:20180105:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.1.6:20151106:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.1:20170120:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.17:20160517:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.4:20120522:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.32:20200930:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.16:20190411:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.26:20190403:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.25:20180606:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.5:20170502:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.51:20230217:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.44:20210927:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.17:20150415:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.15:20140411:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.7:20150116:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.9:20130131:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.11:20150528:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.29:20201019:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.1.3:20140225:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.15:20161220:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.15:20160210:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.16:20170119:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.25:20191220:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.2.2:20101201:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.18:20160721:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.49:20220914:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.1.6:20100715:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.2.1:20101111:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.19:20160209:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.4.5:20110725:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.21:20160908:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.4.2:20110526:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.31:20200723:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.12:20160915:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.1.4:20140401:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.1.1:20100517:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.4:20120522:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.0:20140523:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.46:20220331:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.7:20120910:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.2.0:20101020:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.45:20220203:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.3.0:20110202:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.35:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.5:20120713:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.9:20150224:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.1:20120215:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.7:20120910:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.14:20151106:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.5.2:20111006:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.1.5:20140505:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.39:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.13:20181111:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.5:20141112:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.6:20170531:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.50:20221201:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.27:20190403:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.27:20190418:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.19:20170502:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.5.3:20111011:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.1:20120215:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.34:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.4.3:20110630:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.26:20180806:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.11:20130520:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.20:20161216:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.5:20120713:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.0.6:20130919:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.16:20160407:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.20:20170531:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.36:20210114:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.22:20191022:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.6.15:20140411:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.0:20120125:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.0.1:20091116:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.10:20150310:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.0.0:20091005:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:7.3.1:20110304:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:8.1.14:20131031:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.2.4:20141103:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.4.28:20200408:*:*:*:*:*:*
CPUAPR2026
Oracle Critical Patch Update Advisory - April 2026
CPUJAN2026
Oracle Critical Patch Update Advisory - January 2026
CPUJUL2025
Oracle Critical Patch Update Advisory - July 2025
CPUAPR2025
Oracle Critical Patch Update Advisory - April 2025
CPUJAN2025
Oracle Critical Patch Update Advisory - January 2025
References & Resources
-
https://github.com/jetty/jetty.project/pull/12012emo@eclipse.org Patch Third Party Advisory
-
https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxhemo@eclipse.org Exploit Mitigation Vendor Advisory
-
https://gitlab.eclipse.org/security/cve-assignement/-/issues/25emo@eclipse.org Vendor Advisory
-
https://security.netapp.com/advisory/ntap-20250306-0005/af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
Severity Details
Weakness Type (CWE)
Improper Validation of Syntactic Correctness of Input
- Description
- The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.
- Typical Severity
- Medium
- Abstraction Level
- Base
Key Information
- Published Date
- October 14, 2024
