CVE-2022-2047
jetty9 - security update
2.7
LOW
CVSS 3.1
EPSS 0.40%
Description
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
How to fix CVE-2022-2047
To remediate CVE-2022-2047, upgrade the affected package to a fixed version below.
- —upgrade to 9.4.39-3+deb11u1 or later
- —upgrade to 9.4.16-0+deb10u2 or later
- —upgrade to 9.4.39-3+deb11u1 or later
- —upgrade to 9.4.47 or later
Is CVE-2022-2047 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 9.4.39-3+deb11u1
- from 0, < 9.4.16-0+deb10u2
- from 0, < 9.4.39-3+deb11u1
- from 0, < 9.4.47
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW2.7 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |