PT-2022-6209 · Eclipse+2 · Eclipse Jetty+2

Rafax00

+1

·

Published

2022-07-07

·

Updated

2026-05-18

·

CVE-2022-2047

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Jetty versions 9.4.0 through 9.4.46 Eclipse Jetty versions 10.0.0 through 10.0.9 Eclipse Jetty versions 11.0.0 through 11.0.9
Description The parsing of the authority segment of an http scheme URI in the Jetty HttpURI class improperly detects an invalid input as a hostname, leading to failures in a Proxy scenario. This issue can cause errors with Jetty's HttpClient and Jetty's ProxyServlet, AsyncProxyServlet, and AsyncMiddleManServlet, which wrongly interpret an authority with no host as one with a host. For example, a URI like http://localhost;/path is parsed as having an authority with a host of localhost;, which is incorrect.
Recommendations For Eclipse Jetty versions 9.4.0 through 9.4.46, update to version 9.4.47 or later. For Eclipse Jetty versions 10.0.0 through 10.0.9, update to version 10.0.10 or later. For Eclipse Jetty versions 11.0.0 through 11.0.9, update to version 11.0.10 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-16002
ALT-PU-2024-16022
ALT-PU-2024-16072
BDU:2023-00477
CLEANSTART-2026-SQ91016
CLEANSTART-2026-WK99982
CVE-2022-2047
DLA-3079-1
DSA-5198-1
GHSA-CJ7V-27PG-WF7Q
OESA-2023-1021
OESA-2023-1030
OESA-2023-1031
OESA-2023-1032
OPENSUSE-SU-2024:12182-1

Affected Products

Alt Linux
Astra Linux
Eclipse Jetty