[MAVEN:GHSA-GHGJ-3XQR-6JFM] Jetty vulnerable to exposure of sensitive information to unauthenticated remote users

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

The exception handling code in Eclipse Jetty prior to 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.

Package Affected Version
pkg:maven/org.eclipse.jetty/jetty-server <= 9.2.8.v20150217
Package Fixed Version
pkg:maven/org.eclipse.jetty/jetty-server = 9.2.9.v20150224
ID
MAVEN:GHSA-GHGJ-3XQR-6JFM
Severity
high
URL
https://github.com/advisories/GHSA-ghgj-3xqr-6jfm
Published
2018-11-09T17:50:00
(5 years ago)
Modified
2023-01-08T05:02:40
(20 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.eclipse.jetty/jetty-server org.eclipse.jetty jetty-server <= 9.2.8.v20150217
Fixed pkg:maven/org.eclipse.jetty/jetty-server org.eclipse.jetty jetty-server = 9.2.9.v20150224
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...