VDB
BDU%3A2024-02254
BDU%3A2024-02254
PUBLISHED
CVSS 5 MEDIUM
Уязвимость контейнера сервлетов Eclipse Jetty, связанная с ошибками при обработке параметров длины входных данных, позволяющая нарушителю выполнять атаку «контрабанда HTTP-запросов»
Risk Scores
CVSS 2.0
5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Сообщество свободного программного обеспечения, Red Hat Inc., ООО «Ред Софт», Eclipse Foundation, АО "НППКТ", Elastic NV, Oracle Corp. | OpenSUSE Leap, Debian GNU/Linux, openSUSE Tumbleweed, Red Hat AMQ Broker, Red Hat Integration Camel Quarkus, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise High Performance Computing, Suse Linux Enterprise Desktop, Suse Linux Enterprise Server, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Enterprise Storage, SUSE Linux Enterprise Module for Development Tools, Jetty, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), Red Hat AMQ Streams, Red Hat Integration Camel for Spring Boot, Archi, Communications Cloud Native Core Network Function Cloud Native Environment, A-MQ Clients, OCP Tools, Red Hat Fuse, Red Hat Satellite |
Timeline
- Mar 22, 2024 CVE Published
- Jul 30, 2024 CVE Updated
References
- https://security-tracker.debian.org/tracker/CVE-2023-40167 url
- https://www.suse.com/security/cve/CVE-2023-40167.html url
- https://vuldb.com/?id.251047 url
- https://github.com/jetty/jetty.project/security/advisories/GHSA-hmr7-m48g-48f6 url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.9/ url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://access.redhat.com/security/cve/CVE-2023-40167 advisory
- https://www.oracle.com/security-alerts/cpuoct2023.html advisory