Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6851
HistoryJun 26, 2018 - 2:52 p.m.

HTTP Request Smuggling

2018-06-2614:52:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22

EPSS

0.011

Percentile

84.6%

jetty-http is vulnerable to http request smuggling. The application uses a parser that is too tolerant with deviations from the HTTP header specifications, allowing a malicious user cause a http request smuggling attack through the bad length parsing.

References