PT-2022-6209 · Eclipse+2 · Eclipse Jetty+2
Rafax00
+1
·
Published
2022-07-07
·
Updated
2026-05-18
·
CVE-2022-2047
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Eclipse Jetty versions 9.4.0 through 9.4.46
Eclipse Jetty versions 10.0.0 through 10.0.9
Eclipse Jetty versions 11.0.0 through 11.0.9
Description
The parsing of the authority segment of an http scheme URI in the Jetty HttpURI class improperly detects an invalid input as a hostname, leading to failures in a Proxy scenario. This issue can cause errors with Jetty's HttpClient and Jetty's ProxyServlet, AsyncProxyServlet, and AsyncMiddleManServlet, which wrongly interpret an authority with no host as one with a host. For example, a URI like
http://localhost;/path is parsed as having an authority with a host of localhost;, which is incorrect.Recommendations
For Eclipse Jetty versions 9.4.0 through 9.4.46, update to version 9.4.47 or later.
For Eclipse Jetty versions 10.0.0 through 10.0.9, update to version 10.0.10 or later.
For Eclipse Jetty versions 11.0.0 through 11.0.9, update to version 11.0.10 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Eclipse Jetty