CVE-2024-6763
LowAdvisory
Published 14 Oct 2024In the index since 5 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 3.7
- base score, highest
- EPSS
- 0.010
- 60th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 274
- of 17,781 indexed, latest versions
- Container images
- 253
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Eclipse Jetty URI parsing of invalid authority
Carried by container images the latest versions of 274 of 17,781 indexed charts deploy, on 253 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| jetty-httpmaven | 7.6.0.v20120127, 8.1.7.v20120910, 8.1.9.v20130131, 8.1.12.v20130726+74 more | 12.0.12 | 253 |
- OSV records
- GHSA-qh8g-58pp-2wxh
Charts affected
274 by stars
Container images carrying it
253 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| marcelmay/ | 6292c0a41ffa | jetty-http | 12.0.12 | 8 |
| wurstmeister/ | 2d4bbf9cc83d | jetty-http | 12.0.12 | 7 |
| library/ | b7a76ec06f68 | jetty-http | 12.0.12 | 6 |
| solsson/ | 41e5d8f6f290 | jetty-http | 12.0.12 | 5 |
| bde2020/ | 620267768985 | jetty-http | 12.0.12 | 4 |
| gradiant/ | a1ee6de94c04 | jetty-http | 12.0.12 | 4 |
| quay.io/ | 52f376e64b9b | jetty-http | 12.0.12 | 4 |
| gchq/ | 5ec58edbb2db | jetty-http | 12.0.12 | 3 |
| library/ | 8c5f7881cebb | jetty-http | 12.0.12 | 3 |
| selenium/ | 02f251d48d5f | jetty-http | 12.0.12 | 3 |
| signoz/ | fcc4a3288154 | jetty-http | 12.0.12 | 3 |
| apache/ | 0116fb802786 | jetty-http | 12.0.12 | 2 |
| apache/ | 7cdfd8deec92 | jetty-http | 12.0.12 | 2 |
| apachepulsar/ | b341ef76a852 | jetty-http | 12.0.12 | 2 |
| apache/ | ae0b86d3c4d0 | jetty-http | 12.0.12 | 2 |
| bitnamilegacy/ | 10ed1ea3c8d1 | jetty-http | 12.0.12 | 2 |
| confluentinc/ | ac776fad95a5 | jetty-http | 12.0.12 | 2 |
| confluentinc/ | 7610a50b13e7 | jetty-http | 12.0.12 | 2 |
| confluentinc/ | cae577096489 | jetty-http | 12.0.12 | 2 |
| datagrok/ | f5876d3aebb8 | jetty-http | 12.0.12 | 2 |
| dependencytrack/ | 485ac0952c02 | jetty-http | 12.0.12 | 2 |
| gradiant/ | aae4f8a21f8b | jetty-http | 12.0.12 | 2 |
| gradiant/ | 97657d56e927 | jetty-http | 12.0.12 | 2 |
| jenkins/ | b470bcdc4ecd | jetty-http | 12.0.12 | 2 |
| library/ | 52d3dec8d455 | jetty-http | 12.0.12 | 2 |
| library/ | 56a9453c4064 | jetty-http | 12.0.12 | 2 |
| library/ | 80ad2170ad62 | jetty-http | 12.0.12 | 2 |
| library/ | f258365d4882 | jetty-http | 12.0.12 | 2 |
| linuxserver/ | 9932d6759112 | jetty-http | 12.0.12 | 2 |
| mbentley/ | f4e682274bed | jetty-http | 12.0.12 | 2 |
| metabase/ | 1fb334ce4820 | jetty-http | 12.0.12 | 2 |
| rodolpheche/ | 3be08a386092 | jetty-http | 12.0.12 | 2 |
| ghcr.io/ | 896fc7b18b1b | jetty-http | 12.0.12 | 2 |
| quay.io/ | 02f6f143fc6d | jetty-http | 12.0.12 | 2 |
| 1dev/ | cd5b12fe5471 | jetty-http | 12.0.12 | 1 |
| 5200710/ | 092d3088a5fb | jetty-http | 12.0.12 | 1 |
| 5200710/ | e34ab066d2ed | jetty-http | 12.0.12 | 1 |
| ahmetfurkandemir/ | 142231a0b8b7 | jetty-http | 12.0.12 | 1 |
| aktosecurity/ | 213aded7adc5 | jetty-http | 12.0.12 | 1 |
| aktosecurity/ | 46ed5bcb04b2 | jetty-http | 12.0.12 | 1 |
| alfresco/ | 5472f88d9b0b | jetty-http | 12.0.12 | 1 |
| amazon/ | 1ed00881c937 | jetty-http | 12.0.12 | 1 |
| amazon/ | 8414d80019b0 | jetty-http | 12.0.12 | 1 |
| anguda/ | c435285fc241 | jetty-http | 12.0.12 | 1 |
| apache/ | bae523439ee3 | jetty-http | 12.0.12 | 1 |
| apache/ | a7d9970c148f | jetty-http | 12.0.12 | 1 |
| apache/ | 1f96558fd292 | jetty-http | 12.0.12 | 1 |
| apache/ | 0cef139b6bf1 | jetty-http | 12.0.12 | 1 |
| apache/ | 80136ae753ee | jetty-http | 12.0.12 | 1 |
| apache/ | af361b20bec0 | jetty-http | 12.0.12 | 1 |