Low severity2.7NVD Advisory· Published Jul 7, 2022· Updated Jun 17, 2026
CVE-2022-2047
CVE-2022-2047
Description
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.eclipse.jetty:jetty-httpMaven | < 9.4.47 | 9.4.47 |
org.eclipse.jetty:jetty-httpMaven | >= 10.0.0, < 10.0.10 | 10.0.10 |
org.eclipse.jetty:jetty-httpMaven | >= 11.0.0, < 11.0.10 | 11.0.10 |
Affected products
16- osv-coords7 versionspkg:apk/chainguard/spark-3.5-scala-2.13pkg:maven/org.eclipse.jetty/jetty-httppkg:apk/chainguard/hivepkg:apk/chainguard/hive-compatpkg:apk/chainguard/druidpkg:apk/wolfi/druidpkg:apk/wolfi/spark-3.5-scala-2.13
< 3.5.7-r2+ 6 more
- (no CPE)range: < 3.5.7-r2
- (no CPE)range: < 9.4.47
- (no CPE)range: < 4.0.1-r1
- (no CPE)range: < 4.0.1-r1
- (no CPE)range: < 37.0.0-r14
- (no CPE)range: < 37.0.0-r14
- (no CPE)range: < 3.5.7-r2
- cpe:2.3:a:netapp:element_plug-in_for_vcenter_server:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
- cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- github.com/eclipse/jetty.project/security/advisories/GHSA-cj7v-27pg-wf7qnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-cj7v-27pg-wf7qghsaADVISORY
- lists.debian.org/debian-lts-announce/2022/08/msg00011.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-2047ghsaADVISORY
- security.netapp.com/advisory/ntap-20220901-0006/nvdThird Party Advisory
- www.debian.org/security/2022/dsa-5198nvdThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20220901-0006ghsaWEB
News mentions
0No linked articles in our index yet.