Jetty URI parsing of invalid authority
Published Oct 14, 2024
6.3
MEDIUMCVSS 4.0
EPSS 0.97%
Description
Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.
The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC. Specifically HttpURI and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.
Affected products
-
Affected
- ≥ 7.0.0, ≤ 12.0.11
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Eclipse Foundation | Jetty | unaffected | Affected
|
-
Affected
- ≥ 7.0.0, ≤ 12.0.11
Streams for Apache Kafka 2.9.1
n/a
Fixed · RHSA-2025:9922
Streams for Apache Kafka 3.0.0
n/a
Fixed · RHSA-2025:12511
A-MQ Clients 2
jetty-http
Fix deferred
OpenShift Serverless
jetty-http
Fix deferred
Red Hat AMQ Broker 7
jetty-http
Fix deferred
Red Hat AMQ Clients
jetty-http
Fix deferred
Red Hat Build of Keycloak
jetty-http
Fix deferred
Red Hat Data Grid 8
jetty-http
Fix deferred
Red Hat Fuse 7
jetty-http
Fix deferred
Red Hat Fuse 7
jetty-http-spi
Fix deferred
Red Hat Integration Camel K 1
jetty-http
Fix deferred
Red Hat JBoss Data Grid 7
jetty-http
Fix deferred
Red Hat JBoss Enterprise Application Platform 7
jetty-http
Fix deferred
Red Hat JBoss Enterprise Application Platform 7
jetty-http-spi
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
jetty-http
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
jetty-http-spi
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
jetty-http
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
jetty-http-spi
Fix deferred
Red Hat JBoss Web Server 6
jetty-http
Fix deferred
Red Hat Process Automation 7
jetty-http
Fix deferred
Red Hat Single Sign-On 7
jetty-http
Fix deferred
Red Hat build of Apache Camel - HawtIO 4
jetty-http
Fix deferred
Red Hat build of Apache Camel 4 for Quarkus 3
jetty-http
Fix deferred
Red Hat build of Apache Camel for Spring Boot 3
jetty-http
Fix deferred
Red Hat build of Apache Camel for Spring Boot 4
jetty-http
Fix deferred
Red Hat build of Apicurio Registry 2
jetty-http
Fix deferred
Red Hat build of Debezium 2
jetty-http
Fix deferred
streams for Apache Kafka
jetty-http
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Streams for Apache Kafka 2.9.1 | n/a | Fixed | RHSA-2025:9922 |
| Streams for Apache Kafka 3.0.0 | n/a | Fixed | RHSA-2025:12511 |
| A-MQ Clients 2 | jetty-http | Fix deferred | n/a |
| OpenShift Serverless | jetty-http | Fix deferred | n/a |
| Red Hat AMQ Broker 7 | jetty-http | Fix deferred | n/a |
| Red Hat AMQ Clients | jetty-http | Fix deferred | n/a |
| Red Hat Build of Keycloak | jetty-http | Fix deferred | n/a |
| Red Hat Data Grid 8 | jetty-http | Fix deferred | n/a |
| Red Hat Fuse 7 | jetty-http | Fix deferred | n/a |
| Red Hat Fuse 7 | jetty-http-spi | Fix deferred | n/a |
| Red Hat Integration Camel K 1 | jetty-http | Fix deferred | n/a |
| Red Hat JBoss Data Grid 7 | jetty-http | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jetty-http | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jetty-http-spi | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | jetty-http | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | jetty-http-spi | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jetty-http | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jetty-http-spi | Fix deferred | n/a |
| Red Hat JBoss Web Server 6 | jetty-http | Fix deferred | n/a |
| Red Hat Process Automation 7 | jetty-http | Fix deferred | n/a |
| Red Hat Single Sign-On 7 | jetty-http | Fix deferred | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | jetty-http | Fix deferred | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | jetty-http | Fix deferred | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | jetty-http | Fix deferred | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | jetty-http | Fix deferred | n/a |
| Red Hat build of Apicurio Registry 2 | jetty-http | Fix deferred | n/a |
| Red Hat build of Debezium 2 | jetty-http | Fix deferred | n/a |
| streams for Apache Kafka | jetty-http | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
The attacks outlined above rely on decoded user data being passed to the HttpURI class. Application should not pass decoded user data as an encoded URI to any URI class/method, including HttpURI. Such applications are likely to be vulnerable in other ways.
The immediate solution is to upgrade to a version of the class that will fully validate the characters of the URI authority. Ultimately, Jetty will deprecate and remove support for user info in the authority per RFC9110 Section 4.2.4 https://datatracker.ietf.org/doc/html/rfc9110#section-4.2.4 .
Note that the Chrome (and other browsers) parse the invalid user info section improperly as well (due to flawed WhatWG URL parsing rules that do not apply outside of a Web Browser).
Red Hat statement
For this attack to work, you would require the victim to have a vulnerable browser on top of that the URI being used after insufficient validation, all of which makes this a low-severity flaw.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (10)
- https://access.redhat.com/security/cve/CVE-2024-6763 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2318563 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-3114 Advisory
- https://github.com/advisories/GHSA-qh8g-58pp-2wxh Advisory
- https://github.com/jetty/jetty.project/pull/12012 PatchThird Party Advisory
- https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh ExploitMitigationVendor Advisory
- https://gitlab.eclipse.org/security/cve-assignement/-/issues/25 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-6763
- https://security.netapp.com/advisory/ntap-20250306-0005 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-6763
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-6763 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2318563 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-3114 | Advisory | |
| https://github.com/advisories/GHSA-qh8g-58pp-2wxh | Advisory | |
| https://github.com/jetty/jetty.project/pull/12012 | PatchThird Party Advisory | |
| https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh | ExploitMitigationVendor Advisory | |
| https://gitlab.eclipse.org/security/cve-assignement/-/issues/25 | Vendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-6763 | ||
| https://security.netapp.com/advisory/ntap-20250306-0005 | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2024-6763 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub