StackRadar

CVE-2023-40167

Medium

Advisory

Published 14 Sept 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.011
63rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
183
of 17,781 indexed, latest versions
Container images
165
deployed by those charts
Fix available
1 of 1
affected package

Jetty accepts "+" prefixed value in Content-Length

Carried by container images the latest versions of 183 of 17,781 indexed charts deploy, on 165 images.

Affected packageAffected versionsFixed inImages
jetty-httpmaven9.2.2.v20140723, 9.2.5.v20141112, 9.2.13.v20150730, 9.2.22.v20170606+48 more9.4.52, 10.0.16, 11.0.16165
OSV records
GHSA-hmr7-m48g-48f6

Charts affected

183 by stars
ChartLatestAffected imagesRadar Score
ubooquityhalkeye0.1.11 of 1See more

ubooquity halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jetty-http@9.4.0.v20161208
9.4.52

Open the chart page →

4,303
hazelcast-jethazelcastVerified publisher1.17.11 of 1See more

hazelcast-jet hazelcast 1.17.1

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
jetty-http@9.4.43.v20210629
9.4.52

Open the chart page →

6,102
hbasehbase0.1.72 of 4See more

hbase hbase 0.1.7

2 of the 4 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
jetty-http@9.4.46.v20220331
9.4.52
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
jetty-http@9.4.43.v20210629
9.4.52

Open the chart page →

10,540
helm-airportshelm-airports0.1.01 of 7See more

helm-airports helm-airports 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-http@9.4.43.v20210629
9.4.52

Open the chart page →

12,696
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-http@9.4.43.v20210629
9.4.52

Open the chart page →

4,547
helm-airportshelm-airports-dan0.1.01 of 7See more

helm-airports helm-airports-dan 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-http@9.4.43.v20210629
9.4.52

Open the chart page →

5,573
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-http@9.4.43.v20210629
9.4.52

Open the chart page →

4,547
metabasehelm-charts-nr0.14.41 of 1See more

metabase helm-charts-nr 0.14.4

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
metabase/metabase:v0.45.21fb334ce4820
jetty-http@9.4.48.v20220622
9.4.52

Open the chart page →

2,572
wiremockhelm-charts-nr1.4.61 of 2See more

wiremock helm-charts-nr 1.4.6

1 of the 2 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
jetty-http@9.4.20.v20190813
9.4.52

Open the chart page →

2,140
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
jetty-http@9.4.43.v20210629
9.4.52

Open the chart page →

8,541
heronheron0.20.5-incubating1 of 2See more

heron heron 0.20.5-incubating

1 of the 2 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
apache/bookkeeper:4.14.5a7d9970c148f
jetty-http@9.4.43.v20210629
9.4.52

Open the chart page →

1,449
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
jetty-http@9.4.40.v20210413
9.4.52

Open the chart page →

20,650
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
jetty-http@9.4.48.v20220622
9.4.52

Open the chart page →

7,144
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
jetty-http@9.4.48.v20220622
9.4.52

Open the chart page →

7,862
ibm-kerify-devibm-charts1.0.01 of 1See more

ibm-kerify-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
jetty-http@9.4.11.v20180605
9.4.52

Open the chart page →

8,221
ibm-ws-dyn-agent-devibm-charts1.0.01 of 1See more

ibm-ws-dyn-agent-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
jetty-http@9.2.13.v20150730
9.4.52

Open the chart page →

19,295
ikigaiikigai-chartVerified publisher0.0.92 of 58See more

ikigai ikigai-chart 0.0.9

2 of the 58 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
jetty-http@9.4.51.v20230217
9.4.52
library/zookeeper:3.8-temurin55d1e5b2e601
jetty-http@9.4.51.v20230217
9.4.52

Open the chart page →

37,671
delta-sharing-serverinseefrlab1.2.11 of 1See more

delta-sharing-server inseefrlab 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
deltaio/delta-sharing-server:0.2.08b75118187c5
jetty-http@9.3.27.v20190418
9.4.52

Open the chart page →

6,174
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
jetty-http@9.4.48.v20220622
9.4.52

Open the chart page →

1,754
pinotinseefrlab0.2.02 of 2See more

pinot inseefrlab 0.2.0

2 of the 2 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
jetty-http@9.3.24.v20180605
9.4.52
library/zookeeper:3.5.5b7a76ec06f68
jetty-http@9.4.17.v20190418
9.4.52

Open the chart page →

10,777
itm-mqtt-brokerintelVerified publisher1.0.01 of 1See more

itm-mqtt-broker intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
hivemq/hivemq4:dns-4.5.144d194450d48e
jetty-http@9.4.44.v20210927
9.4.52

Open the chart page →

2,653
thehiveittrident-oss0.1.01 of 6See more

thehive ittrident-oss 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
thehiveproject/cortex:3.1.7f4bc64fb8844
jetty-http@9.4.39.v20210325
9.4.52

Open the chart page →

6,122
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
jetty-http@9.4.5.v20170502
9.4.52

Open the chart page →

10,682
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jetty-http@9.4.30.v20200611
9.4.52

Open the chart page →

12,856
spring-boot-chartjhidalgo3-githubVerified publisher4.0.01 of 1See more

spring-boot-chart jhidalgo3-github 4.0.0

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
jhidalgo3/spring-echo-example:lateste08733191ea0
jetty-http@9.4.35.v20201120
9.4.52

Open the chart page →

1,703
dynamo-dbk8s-home-lab-repo0.0.31 of 1See more

dynamo-db k8s-home-lab-repo 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
amazon/dynamodb-local:1.20.01ed00881c937
jetty-http@9.4.48.v20220622
9.4.52

Open the chart page →

444
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.21.08a4d7e9308de
jetty-http@9.4.49.v20220914
9.4.52

Open the chart page →

12,527
clickhousekubesphere-testVerified publisher0.1.11 of 2See more

clickhouse kubesphere-test 0.1.1

1 of the 2 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
radondb/zookeeper:3.6.216981604f1a0
jetty-http@9.4.24.v20191120
9.4.52

Open the chart page →

6,696
strimzi-kafka-operatorkvalitetsitVerified publisher0.36.11 of 1See more

strimzi-kafka-operator kvalitetsit 0.36.1

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.36.1e9e03b31007c
jetty-http@9.4.51.v20230217
9.4.52

Open the chart page →

4,098
imageboxkyso1.0.01 of 1See more

imagebox kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
kyso/imagebox:latest68091eace89c
jetty-http@9.4.36.v20210114
9.4.52

Open the chart page →

3,833
wiremocklebenitzaVerified publisher0.3.11 of 1See more

wiremock lebenitza 0.3.1

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.27.22328a9fce2bf
jetty-http@9.4.30.v20200611
9.4.52

Open the chart page →

2,427
kafka-connect-wrapperlsmhun0.1.01 of 1See more

kafka-connect-wrapper lsmhun 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
jetty-http@9.4.33.v20201020
9.4.52

Open the chart page →

2,391
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.19.0cafa03b94dac
jetty-http@9.4.43.v20210629
9.4.52

Open the chart page →

12,847
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
jetty-http@9.4.10.v20180503
9.4.52

Open the chart page →

15,855
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
jetty-http@9.4.12.v20180830
9.4.52

Open the chart page →

43,341
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jetty-http@9.4.48.v20220622
9.4.52

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jetty-http@9.4.48.v20220622
9.4.52

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jetty-http@9.4.48.v20220622
9.4.52

Open the chart page →

12,108
backendmojaloop0.1.01 of 6See more

backend mojaloop 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
jetty-http@9.4.43.v20210629
9.4.52

Open the chart page →

16,198
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jetty-http@9.4.48.v20220622
9.4.52

Open the chart page →

11,479
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jetty-http@9.4.48.v20220622
9.4.52

Open the chart page →

19,226
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
jetty-http@9.4.43.v20210629
9.4.52

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
jetty-http@9.4.44.v20210927
9.4.52

Open the chart page →

15,675
datawolfncsaVerified publisher1.1.01 of 3See more

datawolf ncsa 1.1.0

1 of the 3 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
ncsa/datawolf:4.7.0af6649d59150
jetty-http@9.2.2.v20140723
9.4.52

Open the chart page →

4,989
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
jetty-http@9.4.32.v20200930
9.4.52

Open the chart page →

55,726
neo4jneo4j-helm-old4.3.2-11 of 1See more

neo4j neo4j-helm-old 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
jetty-http@9.4.42.v20210604
9.4.52

Open the chart page →

2,640
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-http@9.4.43.v20210629
9.4.52

Open the chart page →

4,547
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
jetty-http@9.4.27.v20200227
9.4.52

Open the chart page →

3,633
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
jetty-http@9.4.43.v20210629
9.4.52

Open the chart page →

8,540
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2023-40167.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
jetty-http@9.4.51.v20230217
9.4.52

Open the chart page →

9,005

Container images carrying it

165 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
jetty-http@9.4.43.v20210629
9.4.52
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jetty-http@9.4.30.v20200611
9.4.52
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
jetty-http@9.4.7.v20170914
9.4.52
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
jetty-http@9.4.43.v20210629
9.4.52
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
jetty-http@9.4.43.v20210629
9.4.52
1
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
jetty-http@9.4.7.v20170914
9.4.52
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
jetty-http@9.4.43.v20210629
9.4.52
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
jetty-http@9.3.11.v20160721
9.4.52
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jetty-http@9.4.12.v20180830
9.4.52
1
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
jetty-http@9.4.12.v20180830
9.4.52
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
jetty-http@9.4.44.v20210927
9.4.52
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
jetty-http@9.4.51.v20230217
9.4.52
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
jetty-http@9.4.48.v20220622
9.4.52
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jetty-http@9.4.11.v20180605
9.4.52
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jetty-http@9.4.51.v20230217
9.4.52
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.