Jetty CVE-2015-2080 Information Disclosure Vulnerability
BID:72768
Info
Jetty CVE-2015-2080 Information Disclosure Vulnerability
| Bugtraq ID: | 72768 |
| Class: | Design Error |
| CVE: |
CVE-2015-2080 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2015 12:00AM |
| Updated: | Feb 24 2015 12:00AM |
| Credit: | Gotham Digital Science and Stephen Komal |
| Vulnerable: |
The Eclipse Foundation Jetty 9.3.0.M1 The Eclipse Foundation Jetty 9.3.0.M0 The Eclipse Foundation Jetty 9.2.8.v20150217 The Eclipse Foundation Jetty 9.2.7.v20150116 The Eclipse Foundation Jetty 9.2.6.v20141205 The Eclipse Foundation Jetty 9.2.5.v20141112 The Eclipse Foundation Jetty 9.2.4.v20141103 The Eclipse Foundation Jetty 9.2.3.v20140905 |
| Not Vulnerable: |
The Eclipse Foundation Jetty 9.2.9.v20150224 |
Discussion
Jetty CVE-2015-2080 Information Disclosure Vulnerability
Jetty is prone to an information-disclosure vulnerability.
Successfully exploiting this issue may allow an attacker to obtain sensitive information that may aid in further attacks.
Jetty is prone to an information-disclosure vulnerability.
Successfully exploiting this issue may allow an attacker to obtain sensitive information that may aid in further attacks.
Exploit / POC
Jetty CVE-2015-2080 Information Disclosure Vulnerability
An attacker can exploit this issue using a readily available tools.
An attacker can exploit this issue using a readily available tools.
Solution / Fix
Jetty CVE-2015-2080 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Jetty CVE-2015-2080 Information Disclosure Vulnerability
References:
References:
- HttpParser Error Buffer Bleed Vulnerability (Jetty)
- JetLeak Vulnerability: Remote Leakage of Shared Buffers in Jetty Web Server [CVE (Jetty)
- Jetty Home Page (The Eclipse Foundation)