CVE-2023-40167
MediumAdvisory
Published 14 Sept 2023In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.011
- 63rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 183
- of 17,781 indexed, latest versions
- Container images
- 165
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Jetty accepts "+" prefixed value in Content-Length
Carried by container images the latest versions of 183 of 17,781 indexed charts deploy, on 165 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| jetty-httpmaven | 9.2.2.v20140723, 9.2.5.v20141112, 9.2.13.v20150730, 9.2.22.v20170606+48 more | 9.4.52, 10.0.16, 11.0.16 | 165 |
- OSV records
- GHSA-hmr7-m48g-48f6
Charts affected
183 by stars
Container images carrying it
165 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| wurstmeister/ | 2d4bbf9cc83d | jetty-http | 9.4.52 | 7 |
| library/ | b7a76ec06f68 | jetty-http | 9.4.52 | 6 |
| solsson/ | 41e5d8f6f290 | jetty-http | 9.4.52 | 5 |
| bde2020/ | 620267768985 | jetty-http | 9.4.52 | 4 |
| gradiant/ | a1ee6de94c04 | jetty-http | 9.4.52 | 4 |
| quay.io/ | 52f376e64b9b | jetty-http | 9.4.52 | 4 |
| gchq/ | 5ec58edbb2db | jetty-http | 9.4.52 | 3 |
| library/ | 8c5f7881cebb | jetty-http | 9.4.52 | 3 |
| selenium/ | 02f251d48d5f | jetty-http | 9.4.52 | 3 |
| signoz/ | fcc4a3288154 | jetty-http | 9.4.52 | 3 |
| apache/ | 0116fb802786 | jetty-http | 9.4.52 | 2 |
| apachepulsar/ | b341ef76a852 | jetty-http | 9.4.52 | 2 |
| bitnamilegacy/ | 10ed1ea3c8d1 | jetty-http | 9.4.52 | 2 |
| confluentinc/ | ac776fad95a5 | jetty-http | 9.4.52 | 2 |
| confluentinc/ | cae577096489 | jetty-http | 9.4.52 | 2 |
| dependencytrack/ | 485ac0952c02 | jetty-http | 10.0.16 | 2 |
| gradiant/ | aae4f8a21f8b | jetty-http | 9.4.52 | 2 |
| gradiant/ | 97657d56e927 | jetty-http | 9.4.52 | 2 |
| library/ | 56a9453c4064 | jetty-http | 9.4.52 | 2 |
| library/ | 80ad2170ad62 | jetty-http | 9.4.52 | 2 |
| linuxserver/ | 9932d6759112 | jetty-http | 9.4.52 | 2 |
| mbentley/ | f4e682274bed | jetty-http | 9.4.52 | 2 |
| metabase/ | 1fb334ce4820 | jetty-http | 9.4.52 | 2 |
| rodolpheche/ | 3be08a386092 | jetty-http | 9.4.52 | 2 |
| 5200710/ | 092d3088a5fb | jetty-http | 9.4.52 | 1 |
| 5200710/ | e34ab066d2ed | jetty-http | 9.4.52 | 1 |
| amazon/ | 1ed00881c937 | jetty-http | 9.4.52 | 1 |
| anguda/ | c435285fc241 | jetty-http | 9.4.52 | 1 |
| apache/ | a7d9970c148f | jetty-http | 9.4.52 | 1 |
| apache/ | 1f96558fd292 | jetty-http | 9.4.52 | 1 |
| apache/ | 0cef139b6bf1 | jetty-http | 9.4.52 | 1 |
| apache/ | 80136ae753ee | jetty-http | 9.4.52 | 1 |
| apache/ | af361b20bec0 | jetty-http | 9.4.52 | 1 |
| apacheignite/ | d7deab68b8fa | jetty-http | 9.4.52 | 1 |
| apache/ | 8647309f95d1 | jetty-http | 9.4.52 | 1 |
| apache/ | afa47bf1692a | jetty-http | 9.4.52 | 1 |
| apache/ | 090b7f87ec7f | jetty-http | 9.4.52 | 1 |
| apache/ | 974efa2f21da | jetty-http | 9.4.52 | 1 |
| apachepinot/ | 0018bb04ced7 | jetty-http | 9.4.52 | 1 |
| apachepulsar/ | 16f9fdab3fa6 | jetty-http | 9.4.52 | 1 |
| apachepulsar/ | 3b262ab7a7d9 | jetty-http | 9.4.52 | 1 |
| apachepulsar/ | 4db6ff0b4045 | jetty-http | 9.4.52 | 1 |
| apachepulsar/ | d056c89b7131 | jetty-http | 9.4.52 | 1 |
| apachepulsar/ | d538416d5afe | jetty-http | 9.4.52 | 1 |
| apache/ | 641237e0299b | jetty-http | 9.4.52 | 1 |
| apache/ | b4ec8c18d079 | jetty-http | 9.4.52 | 1 |
| apache/ | 92d055a84e9e | jetty-http | 9.4.52 | 1 |
| apimap/ | ae2b3ab00177 | jetty-http | 9.4.52 | 1 |
| assistiot/ | ae8b3d72eb5d | jetty-http | 9.4.52 | 1 |
| assistiot/ | c8b6c7eaa0cd | jetty-http | 9.4.52 | 1 |