---
title: "CVE-2024-6763\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2024-6763?format=md
keywords: index, follow
---

# CVE-2024-6763

Publication date 14 October 2024

Last updated 30 June 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**3.7 · Low**

[Score breakdown](https://ubuntu.com/security/CVE-2024-6763?format=md#impact-score)

Toggle side navigation

## Description

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and
Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.
The HttpURI class does insufficient validation on the authority segment of
a URI. However the behaviour of HttpURI
differs from the common browsers in how it handles a URI that would be
considered invalid if fully validated against the RRC. Specifically
HttpURI
and the browser may differ on the value of the host extracted from an
invalid URI and thus a combination of Jetty and a vulnerable browser may
be vulnerable to a open redirect attack or to a SSRF attack if the URI
is used after passing validation checks.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| jetty | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 25.04 plucky | Not in release |
| 24.10 oracular | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Not in release |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Needs evaluation |
| jetty9 | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Ignored end of life, was needed |
| 24.04 LTS noble | Vulnerable |
| 22.04 LTS jammy | Vulnerable |
| 20.04 LTS focal | Vulnerable |
| 18.04 LTS bionic | Vulnerable |
| 16.04 LTS xenial | Vulnerable |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2024-6763?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| jetty9 | * Upstream:   [db8bb7a](https://github.com/jetty/jetty.project/commit/db8bb7a8631aafc7897032b133a5b425854e5841) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

3.7 · Low

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | Low |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 3.7 · Low |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6763)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2024-6763)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2024-6763)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2024-6763)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2024-6763>
* <https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh>
* <https://github.com/jetty/jetty.project/pull/12012>
