CVE-2025-11143
Estado: AnalizadaMedia (6.5)—
The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-11143",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-11143",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-03-05T14:48:27.345884Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "emo@eclipse.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "emo@eclipse.org",
"affectedData": [
{
"repo": "https://github.com/jetty/jetty.project",
"vendor": "Eclipse Foundation",
"product": "Eclipse Jetty",
"versions": [
{
"status": "affected",
"version": "9.4.0",
"versionType": "semver",
"lessThanOrEqual": "9.4.58"
},
{
"status": "affected",
"version": "10.0.0",
"versionType": "semver",
"lessThanOrEqual": "10.0.26"
},
{
"status": "affected",
"version": "11.0.0",
"versionType": "semver",
"lessThanOrEqual": "11.0.26"
},
{
"status": "affected",
"version": "12.0.0",
"versionType": "semver",
"lessThanOrEqual": "12.0.30"
},
{
"status": "affected",
"version": "12.1.0",
"versionType": "semver",
"lessThanOrEqual": "12.1.4"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-03-05T10:15:54.680",
"references": [
{
"url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-wjpw-4j6x-6rwh",
"tags": [
"Vendor Advisory"
],
"source": "emo@eclipse.org"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "emo@eclipse.org",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details."
},
{
"lang": "es",
"value": "El analizador URI de Jetty tiene algunas diferencias clave con respecto a otros analizadores comunes al evaluar URIs inválidas o inusuales. El análisis diferencial de URIs en sistemas que utilizan múltiples componentes puede resultar en una elusión de seguridad. Por ejemplo, un componente que aplica una lista negra puede interpretar las URIs de manera diferente de uno que genera una respuesta. Como mínimo, el análisis diferencial puede divulgar detalles de implementación."
}
],
"lastModified": "2026-06-17T08:29:44.717",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D6BB4322-1158-46D7-8A04-2B4FBC3941A4",
"versionEndIncluding": "9.4.58",
"versionStartIncluding": "9.4.0"
},
{
"criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "56F09A5B-49C1-406A-B4F6-D6F2D3FA660E",
"versionEndIncluding": "10.0.26",
"versionStartIncluding": "10.0.0"
},
{
"criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B1CFB36-11A3-449E-BDDF-7837CE9E1511",
"versionEndIncluding": "11.0.26",
"versionStartIncluding": "11.0.0"
},
{
"criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDBDC172-58CA-4579-8A14-05977FE1E453",
"versionEndExcluding": "12.0.31",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E18C4D9-4B42-40A6-9630-F844F0C83910",
"versionEndExcluding": "12.1.5",
"versionStartIncluding": "12.1.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "emo@eclipse.org"
}