Lucene search

K
osvGoogleOSV:GHSA-84Q7-P226-4X5W
HistoryOct 19, 2018 - 4:16 p.m.

Jetty vulnerable to cache poisoning due to inconsistent HTTP request handling (HTTP Request Smuggling)

2018-10-1916:16:27
Google
osv.dev
26

0.012 Low

EPSS

Percentile

85.3%

Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), contain an HTTP Request Smuggling Vulnerability that can result in cache poisoning.

References