CVE-2017-7657 Details
Description
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | [email protected] |
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| eclipse jetty | <= 9.2.26 >= 9.3.0, < 9.3.24 >= 9.4.0, < 9.4.11 |
CPE
Remediation
| |
| debian debian linux | 9.0 |
CPE
Remediation
| |
| netapp e-series santricity management | All versions |
CPE
Remediation
| |
| netapp e-series santricity os controller | >= 11.0, <= 11.50.1 |
CPE
Remediation
| |
| netapp e-series santricity web services | All versions |
CPE
Remediation
| |
| netapp element software | All versions |
CPE
Remediation
| |
| netapp element software management node | All versions |
CPE
Remediation
| |
| netapp hci storage nodes | All versions |
CPE
Remediation
| |
| netapp oncommand system manager | 3.x |
CPE
Remediation
| |
| netapp oncommand unified manager | < 5.2.4 |
CPE
Remediation
| |
| netapp santricity cloud connector | All versions |
CPE
Remediation
| |
| netapp snap creator framework | < 4.3.3 |
CPE
Remediation
| |
| netapp snapcenter | < 4.1p3 |
CPE
Remediation
| |
| netapp snapmanager | < 3.4.2 |
CPE
Remediation
| |
| hp xp p9000 command view | >= 8.4.0-00, < 8.6.2-00 |
CPE
Remediation
| |
| hp xp p9000 | All versions |
CPE
Remediation
| |
| oracle rest data services | 11.2.0.4 12.1.0.2 12.2.0.1 18c |
CPE
Remediation
| |
| oracle retail xstore point of service | 7.1 15.0 16.0 17.0 |
CPE
Remediation
| |
Change History
22 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Jul 20, 2021 | CVE Modified | [email protected] |
| Mar 5, 2021 | CVE Modified | [email protected] |
| Mar 4, 2021 | Modified Analysis | [email protected] |
| Feb 26, 2021 | CVE Modified | [email protected] |
| Oct 20, 2020 | CVE Modified | [email protected] |
| Jul 29, 2020 | CVE Modified | [email protected] |
| Nov 16, 2019 | CVE Modified | [email protected] |
| Nov 12, 2019 | CVE Modified | [email protected] |
| Oct 16, 2019 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Aug 22, 2019 | CVE Modified | [email protected] |
| Aug 21, 2019 | CVE Modified | [email protected] |
| May 15, 2019 | Modified Analysis | [email protected] |
| Apr 30, 2019 | CVE Modified | [email protected] |
| Oct 16, 2018 | CVE Modified | [email protected] |
| Aug 23, 2018 | Initial Analysis | [email protected] |
| Aug 20, 2018 | CVE Modified | [email protected] |
| Jun 29, 2018 | CVE Modified | [email protected] |