The vendor explicitly identifies these products as affected by this CVE.
- jenkins.src as a component of OpenShift Developer Tools and Services
- jetty-http as a component of Red Hat Decision Manager 7
- jetty-http as a component of Red Hat Integration Service Registry
- jetty-http as a component of Red Hat JBoss Data Grid 7
- jetty-http as a component of Red Hat JBoss Enterprise Application Platform 6
- jetty-http as a component of Red Hat JBoss Fuse 6
- jetty-http as a component of Red Hat JBoss Fuse Service Works 6
- opendaylight as a component of Red Hat OpenStack Platform 13 (Queens)
- opendaylight.src as a component of Red Hat OpenStack Platform 13 (Queens)
- jetty-http as a component of Red Hat Process Automation 7
- Summary
- A flaw was found in Eclipse Jetty. When parsing the authority segment of an HTTP scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This issue can lead to failures in a Proxy scenario.
- Remediation
- Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings. The References section of this erratum contains a download link (you must log in to download the update).
