HTTP request smuggling attack in Jetty - CVE-2017-7658

 

HTTP request smuggling attack in Jetty - CVE-2017-7658

Published: July 2, 2018


Vulnerability identifier: #VU13529
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7658
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to conduct an HTTP request smuggling attack on the target system.

The vulnerability exists due to improper handling HTTP requests that contain more than one content-length header. A remote attacker can send a specially crafted HTTP request that contains a transfer-encoding header and a content-length header, cause the software and an upstream HTTP agent to misinterpret the boundary of the request and to poison the web cache on the system, which could be used to conduct further attacks.


Affected software

Jetty
Debian Linux
Fedora
Security Directory Integrator
Oracle Retail Xstore Payment
Cloudera Observability with IBM
IBM Security Verify Directory
Dell Support Assist Enterprise
IBM Security Directory Suite
BIG-IP
Dell Secure Connect Gateway
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Cloud Application Performance Management (APM)
IBM Spectrum Protect Storage Agent
IBM Security Verify Governance
BIG-IQ Centralized Management
Oracle REST Data Services
Cloudera Data Platform Private Cloud Base for IBM
jetty
IBM Cognos Command Center

How to mitigate CVE-2017-7658

The vulnerability is addressed in the versions 9.2.25.v2018060, 9.3.24.v20180605 and 9.4.11.v20180605.

Jetty - addressed in versions 9.2.25.v2018060, 9.3.24.v20180605, 9.4.11.v20180605
Dell Secure Connect Gateway - update to 5.12.00.10
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.29
Dell Support Assist Enterprise - update to 2.0.21
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.7 SP2 Cumulative Hotfix 16
IBM Security Directory Suite - update to 8.0.1.21
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Spectrum Protect Storage Agent - update to 8.1.19
jetty - addressed in versions 9.4.11-2.v20180605.fc27, 9.4.11-2.v20180605.fc28
IBM Security Verify Governance - update to 10.0.1.0.3
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17

External References

Related Security Bulletins