|
|
|
![]() |
Vulnerability Note VU#212984Mortbay Jetty vulnerable to HTTP response splittingOverviewMortbay Jetty is vulnerable to HTTP response splitting, which may allow a remote, unauthenticated attacker to inject various HTTP headersI. DescriptionMortbay Jetty is a web server that is written in Java. Jetty fails to properly handle HTTP headers with CRLF sequences, which can allow an attacker to inject certain HTTP headers into server responses.II. ImpactA remote, unauthenticated attacker may be able to perform a cross-site scripting attack, set cookies, or poison a proxy cache.III. SolutionApply an updateThis issue is addressed in Mortbay Jetty 6.1.6. Details are available in the release notes.
References
Thanks to Tomasz Kuczynski for reporting this vulnerability. This document was written by Will Dormann.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||