DirectorySecurity Advisories
Sign In
Security Advisories

CGA-x64f-h9cm-wv76

Published

Last updated

https://images.chainguard.dev/security/CGA-x64f-h9cm-wv76
Package

spark-3.5-scala-2.13

Latest Update
Pending upstream fix
Aliases
  • CVE-2022-2047
  • GHSA-cj7v-27pg-wf7q

Severity

2.7

Low

CVSS V3

Summary

Jetty invalid URI parsing may produce invalid HttpURI.authority

Description

Description

URI use within Jetty's HttpURI class can parse invalid URIs such as http://localhost;/path as having an authority with a host of localhost;.

A URIs of the type http://localhost;/path should be interpreted to be either invalid or as localhost; to be the userinfo and no host. However, HttpURI.host returns localhost; which is definitely wrong.

Impact

This can lead to errors with Jetty's HttpClient, and Jetty's ProxyServlet / AsyncProxyServlet / AsyncMiddleManServlet wrongly interpreting an authority with no host as one with a host.

Patches

Patched in PR #8146 for Jetty version 9.4.47. Patched in PR #8014 for Jetty versions 10.0.10, and 11.0.10

Workarounds

None.

For more information

If you have any questions or comments about this advisory:

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images