Eclipse / Jetty.project
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-36478 | HTTP/2 HPACK integer overflow and buffer allocation | HIGH | 7.5 | Oct 10, 2023 |
| CVE-2023-41900 | Jetty's OpenId Revoked authentication allows one request | MEDIUM | 4.3 | Sep 15, 2023 |
| CVE-2023-40167 | Jetty accepts "+" prefixed value in Content-Length | MEDIUM | 5.3 | Sep 15, 2023 |
| CVE-2023-36479 | Jetty vulnerable to errant command quoting in CGI Servlet | LOW | 3.5 | Sep 15, 2023 |
| CVE-2023-26049 | Cookie parsing of quoted values can exfiltrate values from other cookies in Eclipse Jetty | MEDIUM | 5.3 | Apr 18, 2023 |
| CVE-2023-26048 | OutOfMemoryError for large multipart without filename in Eclipse Jetty | MEDIUM | 5.3 | Apr 18, 2023 |
Showing 1 to 6 of 6 CVEs