Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7108
HistoryJul 19, 2018 - 8:32 a.m.

Request Smuggling

2018-07-1908:32:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23

0.007 Low

EPSS

Percentile

80.9%

jetty is vulnerable to request smuggling. An integer overflow in the chunk length parsing causes a large chunk size to be interpreted as a smaller chunk size. As a result, the content in the chunk body is interpreted as a pipelined request which can be exploited by an attacker to bypass authorization.

References