QID 982307
QID 982307: Java (maven) Security Update for org.eclipse.jetty:jetty-server (GHSA-ghgj-3xqr-6jfm)
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-ghgj-3xqr-6jfm for updates pertaining to this vulnerability.
Vendor References
- GHSA-ghgj-3xqr-6jfm -
github.com/advisories/GHSA-ghgj-3xqr-6jfm
CVEs related to QID 982307
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-ghgj-3xqr-6jfm | org.eclipse.jetty:jetty-server |
|