{"id":"CVE-2007-5615","aliases":[],"url":"https://o3.security/vulnerability/CVE-2007-5615","summary":"Mortbay Jetty CRLF Injection Vulnerability","details":"CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.","published":"2022-05-01T18:35:01Z","modified":"2024-12-03T06:26:22.232759Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.mortbay.jetty:jetty","fixedVersion":"6.1.6rc0"}],"fix":{"url":"https://github.com/jetty-project/codehaus-jetty6/commit/0d2592ea3183914163d0921e4855bd3e18582a05","label":"jetty-project/codehaus-jetty6@0d2592e"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5615"},{"type":"WEB","url":"https://github.com/jetty-project/codehaus-jetty6/commit/0d2592ea3183914163d0921e4855bd3e18582a05"},{"type":"WEB","url":"https://web.archive.org/web/20071007232422/http://svn.codehaus.org:80/jetty/jetty/trunk/VERSION.txt"},{"type":"WEB","url":"https://web.archive.org/web/20150112202621/http://www.securityfocus.com/bid/26696"},{"type":"WEB","url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00227.html"},{"type":"WEB","url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00250.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html"},{"type":"WEB","url":"http://www.kb.cert.org/vuls/id/212984"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-03T06:26:22.232759Z"}}