CVE-2023-40167
MediumAdvisory
Published 14 Sept 2023In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.011
- 63rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 183
- of 17,781 indexed, latest versions
- Container images
- 165
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Jetty accepts "+" prefixed value in Content-Length
Carried by container images the latest versions of 183 of 17,781 indexed charts deploy, on 165 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| jetty-httpmaven | 9.2.2.v20140723, 9.2.5.v20141112, 9.2.13.v20150730, 9.2.22.v20170606+48 more | 9.4.52, 10.0.16, 11.0.16 | 165 |
- OSV records
- GHSA-hmr7-m48g-48f6
Charts affected
183 by stars
Container images carrying it
165 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| assistiot/ | ea254b6d8a31 | jetty-http | 9.4.52 | 1 |
| atlassian/ | 3b9222ab32ef | jetty-http | 9.4.52 | 1 |
| bitnamilegacy/ | 8657bb93a581 | jetty-http | 9.4.52 | 1 |
| bitnamilegacy/ | ac64829e45b3 | jetty-http | 9.4.52 | 1 |
| bitnamilegacy/ | b6e381ffd6ae | jetty-http | 9.4.52 | 1 |
| bitnamilegacy/ | dba59d740e13 | jetty-http | 9.4.52 | 1 |
| bivas/ | 05545994f806 | jetty-http | 9.4.52 | 1 |
| commerceexperts/ | 9e33ad89baf6 | jetty-http | 9.4.52 | 1 |
| confluentinc/ | f2975d507a2a | jetty-http | 9.4.52 | 1 |
| confluentinc/ | 8f1544df1f48 | jetty-http | 9.4.52 | 1 |
| confluentinc/ | 1bbda887bc53 | jetty-http | 9.4.52 | 1 |
| confluentinc/ | 3bf359d5e340 | jetty-http | 9.4.52 | 1 |
| confluentinc/ | c87b1c07fb53 | jetty-http | 9.4.52 | 1 |
| confluentinc/ | dc9b972db002 | jetty-http | 9.4.52 | 1 |
| confluentinc/ | 4bc70a83ca6f | jetty-http | 9.4.52 | 1 |
| confluentinc/ | b0b7aa26254a | jetty-http | 9.4.52 | 1 |
| confluentinc/ | ee403d5b9090 | jetty-http | 9.4.52 | 1 |
| confluentinc/ | b651d4b6185a | jetty-http | 9.4.52 | 1 |
| confluentinc/ | 0bec03c1f3ce | jetty-http | 9.4.52 | 1 |
| confluentinc/ | 78c190f4472c | jetty-http | 9.4.52 | 1 |
| craigwillis/ | ae317d7e4724 | jetty-http | 9.4.52 | 1 |
| datappeal/ | e38c085a3567 | jetty-http | 9.4.52 | 1 |
| dbanda/ | 0ca125e68e53 | jetty-http | 9.4.52 | 1 |
| dbanda/ | d0e6367876ae | jetty-http | 9.4.52 | 1 |
| deltaio/ | 8b75118187c5 | jetty-http | 9.4.52 | 1 |
| dniel/ | 45a667852f2a | jetty-http | 9.4.52 | 1 |
| dremio/ | 80ed2e3b7c43 | jetty-http | 9.4.52 | 1 |
| duck1123/ | 119fc5d4cbfb | jetty-http | 9.4.52 | 1 |
| easypi/ | d2950a36a576 | jetty-http | 9.4.52 | 1 |
| farberg/ | 4b4a22487394 | jetty-http | 9.4.52 | 1 |
| fimperato/ | 604012b77841 | jetty-http | 9.4.52 | 1 |
| folioci/ | 29c3f233a498 | jetty-http | 9.4.52 | 1 |
| folioci/ | cfd6109bf477 | jetty-http | 9.4.52 | 1 |
| folioci/ | ae3b069d4ba5 | jetty-http | 9.4.52 | 1 |
| folioci/ | 571fa1ffe8c9 | jetty-http | 9.4.52 | 1 |
| folioci/ | f53c327a48e8 | jetty-http | 9.4.52 | 1 |
| fonoster/ | 2ca65af17cbc | jetty-http | 9.4.52 | 1 |
| fonoster/ | d08a8a574a50 | jetty-http | 11.0.16 | 1 |
| fonoster/ | e0c823506eb2 | jetty-http | 11.0.16 | 1 |
| frankescobar/ | 8a4d7e9308de | jetty-http | 9.4.52 | 1 |
| frankescobar/ | cafa03b94dac | jetty-http | 9.4.52 | 1 |
| gchq/ | c460bb587d6d | jetty-http | 9.4.52 | 1 |
| geonetwork/ | 20c9bb761f67 | jetty-http | 9.4.52 | 1 |
| gocd/ | 2da45cb09d57 | jetty-http | 9.4.52 | 1 |
| gradiant/ | e3bf364fe713 | jetty-http | 9.4.52 | 1 |
| gradiant/ | 45eceb1bc55c | jetty-http | 9.4.52 | 1 |
| gurolakman/ | 9abb3882bcbd | jetty-http | 9.4.52 | 1 |
| gurolakman/ | ce23b20a8a17 | jetty-http | 9.4.52 | 1 |
| gurolakman/ | b22e746edd5d | jetty-http | 9.4.52 | 1 |
| gurolakman/ | bf18525c5ad9 | jetty-http | 9.4.52 | 1 |