CVE-2024-6763
Jetty URI parsing of invalid authority
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.
A flaw was found in Jetty. The HttpURI class performs insufficient validation on the authority segment of a URI. The HttpURI and the browser may differ on the value of the host extracted from an invalid URI. This combination of Jetty and a vulnerable browser may be vulnerable to an open redirect attack or an SSRF attack if the URI is used after passing validation checks.
This update for jetty-minimal fixes the following issues. Upgrade to version 9.4.57.v20241219 the HttpURI class does insufficient validation on the authority segment of a URI Gzip Request Body Buffer.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-07-15 CVE Reserved
- 2024-10-14 CVE Published
- 2025-03-07 CVE Updated
- 2025-07-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1286: Improper Validation of Syntactic Correctness of Input
CAPEC
References (5)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2024-6763 | 2025-06-30 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2318563 | 2025-06-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eclipse Foundation Search vendor "Eclipse Foundation" | Jetty Search vendor "Eclipse Foundation" for product "Jetty" | >= 7.0.0 <= 12.0.11 Search vendor "Eclipse Foundation" for product "Jetty" and version " >= 7.0.0 <= 12.0.11" | en |
Affected
|