Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6849
HistoryJun 26, 2018 - 12:30 p.m.

HTTP Request Smuggling

2018-06-2612:30:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
27

0.012 Low

EPSS

Percentile

85.3%

jetty-http is vulnerable to HTTP request smuggling attacks. The HTTP parser accepts request headers when the HTTP/0.9 protocol specifically has none, allowing a malicious user to conduct HTTP request smuggling attacks.

References