CVE Vulnerabilities

CVE-2007-5614

Published: Dec 05, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Mortbay Jetty before 6.1.6rc1 does not properly handle certain quote sequences in HTML cookie parameters, which allows remote attackers to hijack browser sessions via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
JettyMortbay_jetty1.0 (including)1.0 (including)
JettyMortbay_jetty2.4 (including)2.4 (including)
JettyMortbay_jetty3.0 (including)3.0 (including)
JettyMortbay_jetty3.1 (including)3.1 (including)
JettyMortbay_jetty4.0 (including)4.0 (including)
JettyMortbay_jetty4.1 (including)4.1 (including)
JettyMortbay_jetty4.2 (including)4.2 (including)
JettyMortbay_jetty5 (including)5 (including)
JettyMortbay_jetty5.1 (including)5.1 (including)
JettyMortbay_jetty6 (including)6 (including)
JettyMortbay_jetty6.1 (including)6.1 (including)

References