CVE-2017-7658: Debian Linux
Critical severity, CVSS 9.8. EPSS: 19.4% chance of exploitation in the next 30 days.
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.
Affected products
- Debian Debian Linux: version 9.0 only
- Eclipse Jetty: up to and including 9.2.26; from 9.3.0, before 9.3.24 (fixed in 9.3.24); from 9.4.0, before 9.4.11 (fixed in 9.4.11)
- HP XP p9000 Command View: from 8.4.0-00, up to and including 8.6.2-00
- Netapp E-Series Santricity Management: affected versions not specified
- Netapp E-Series Santricity OS Controller: from 11.0, up to and including 11.50.1
- Netapp E-Series Santricity Web Services: affected versions not specified
- Netapp Hci Management Node: affected versions not specified
- Netapp Hci Storage Node: affected versions not specified
- Netapp Oncommand System Manager: from 3.0, up to and including 3.1.3
- Netapp Oncommand Unified Manager For 7-Mode: affected versions not specified
- Netapp Santricity Cloud Connector: affected versions not specified
- Netapp Snap Creator Framework: affected versions not specified
- Netapp Snapcenter: affected versions not specified
- Netapp Snapmanager: affected versions not specified
- Netapp Solidfire: affected versions not specified
- Netapp Storage Services Connector: affected versions not specified
- Oracle Rest Data Services: version 11.2.0.4 only; version 12.1.0.2 only; version 12.2.0.1 only; version 18c only
- Oracle Retail Xstore Payment: version 3.3 only
- Oracle Retail Xstore Point Of Service: version 7.1 only; version 15.0 only; version 16.0 only; version 17.0 only
Published 2018-06-26. Last modified 2026-06-17.