The vendor explicitly identifies these products as affected by this CVE.
- jenkins.src as a component of OpenShift Developer Tools and Services
- ocp-tools-4/jenkins-rhel8 as a component of OpenShift Developer Tools and Services
- ocp-tools-4/jenkins-rhel9 as a component of OpenShift Developer Tools and Services
- jetty-server as a component of Red Hat AMQ Broker 7
- jetty-server as a component of Red Hat build of Apache Camel - HawtIO 4
- jetty-server as a component of Red Hat build of Apache Camel for Spring Boot 4
- jetty-server as a component of Red Hat build of Apicurio Registry 3
- jetty-server as a component of Red Hat build of Debezium 3
- jetty-server as a component of Red Hat Data Grid 8
- maven-site-plugin-javadoc as a component of Red Hat Enterprise Linux 7
- maven-site-plugin.src as a component of Red Hat Enterprise Linux 7
- resteasy-javadoc (pki-core:10.6) as a component of Red Hat Enterprise Linux 8
- Summary
- A flaw was found in Eclipse Jetty. The server does not strictly validate that the request authority (host and port) matches the Host header provided in HTTP/1, HTTP/2, and HTTP/3 requests. This improper validation can lead to various issues, including incorrect handling of URI constructions for redirects, flawed virtual host selection, and problems with reverse proxying. Such discrepancies could potentially be exploited to bypass security mechanisms or misroute network traffic.
- Remediation
- Fix deferred
