VDB
BDU%3A2022-02206
BDU%3A2022-02206
PUBLISHED
CVSS 10 CRITICAL
Уязвимость реализации протокола Hypertext Transfer Protocol (HTTP/1.1) контейнера сервлетов Eclipse Jetty, позволяющая нарушителю отправить скрытый HTTP-запрос (атака типа HTTP Request Smuggling)
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Oracle Corp., Eclipse Foundation, IBM Corp., Apache Software Foundation, HP Inc. | Debian GNU/Linux, Retail Xstore Payment, Enterprise Manager Base Platform, Oracle Hospitality Guest Access, Jetty, REST Data Services, Cognos Analytics, Oracle Communications Cloud Native Core Policy, BookKeeper, HP Device Manager, Oracle Retail Xstore Point of Service |
Timeline
- Apr 13, 2022 CVE Published
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
References
- http://www.securityfocus.com/bid/106566 url
- http://www.securitytracker.com/id/1041194 url
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=535669 url
- https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272@%3Cissues.activemq.apache.org%3E url
- https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E url
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E url
- https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E url
- https://lists.apache.org/thread.html/r41af10c4adec8d34a969abeb07fd0d6ad0c86768b751464f1cdd23e8@%3Ccommits.druid.apache.org%3E url
- https://lists.apache.org/thread.html/r9159c9e7ec9eac1613da2dbaddbc15691a13d4dbb2c8be974f42e6ae@%3Ccommits.druid.apache.org%3E url
- https://lists.apache.org/thread.html/ra6f956ed4ec2855583b2d0c8b4802b450f593d37b77509b48cd5d574@%3Ccommits.druid.apache.org%3E url
- https://security.netapp.com/advisory/ntap-20181014-0001/ url
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03953en_us url
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html url
- https://github.com/advisories/GHSA-6x9x-8qw9-9pp6 url
- https://www.eclipse.org/jetty/security_reports.php advisory
- https://www.debian.org/security/2018/dsa-4278 advisory
- https://www.oracle.com//security-alerts/cpujul2021.html advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html advisory
- https://lists.apache.org/thread/gg49mcoofz9w3t9rbm7w61ntqg2xqr3l advisory
…and 2 more