Back

HIGH

jetty: remote unauthenticated credential exposure

Published Oct 7, 2016

Description

The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of jetty as shipped with Red Hat Enterprise Linux 7, versions of openshift-origin-cartridge-fuse as shipped with Red Hat OpenShift Enterprise 2.1, and versions of nutch as shipped with Red Hat Satellite 5.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 7, 2016
Updated Aug 6, 2024
Reserved Feb 24, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 24, 2015
GHSA-GHGJ-3XQR-6JFM