{"id":"CVE-2007-5614","aliases":[],"url":"https://o3.security/vulnerability/CVE-2007-5614","summary":"Improper Authentication in Mortbay Jetty","details":"Mortbay Jetty before 6.1.6rc1 does not properly handle \"certain quote sequences\" in HTML cookie parameters, which allows remote attackers to hijack browser sessions via unspecified vectors.","published":"2022-05-01T18:35:01Z","modified":"2026-09-10T03:49:22.634182246Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.mortbay.jetty:jetty","fixedVersion":"6.1.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5614"},{"type":"PACKAGE","url":"https://github.com/eclipse/jetty.project"},{"type":"WEB","url":"https://www.eclipse.org/jetty/about.php"},{"type":"WEB","url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00227.html"},{"type":"WEB","url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00250.html"},{"type":"WEB","url":"http://www.kb.cert.org/vuls/id/438616"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:49:22.634182246Z"}}