jetty: double release of resource can lead to information disclosure
Published Jul 9, 2020
9.4
CRITICALCVSS 3.1
EPSS 11.14%
Description
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP response headers is released back to the ByteBufferPool twice. Because of this double release, two threads can acquire the same ByteBuffer from the pool and while thread1 is about to use the ByteBuffer to write response1 data, thread2 fills the ByteBuffer with other data. Thread1 then proceeds to write the buffer that now contains different data. This results in client1, which issued request1 seeing data from another request or response which could contain sensitive data belonging to client2 (HTTP session ids, authentication credentials, etc.). If the Jetty version cannot be upgraded, the vulnerability can be significantly reduced by configuring a responseHeaderSize significantly larger than the requestHeaderSize (12KB responseHeaderSize and 8KB requestHeaderSize).
Affected products
-
- Version 9.4.27.v20200227 to 9.4.29.v20200521StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Eclipse Foundation | Eclipse Jetty | n/a |
|
No data.
Red Hat Fuse 7.8.0
jetty
Fixed · RHSA-2020:5568
Red Hat OpenShift Container Platform 3.11
jenkins-0:2.235.5.1600415953-1.el7
Fixed · RHSA-2020:4223
Red Hat OpenShift Container Platform 4.3
jenkins-0:2.235.5.1600415514-1.el7
Fixed · RHSA-2020:3808
Red Hat OpenShift Container Platform 4.4
openshift4/ose-jenkins:v4.4.0-202009260441.p0
Fixed · RHSA-2020:4220
Red Hat OpenShift Container Platform 4.5
jenkins-0:2.235.5.1600414805-1.el7
Fixed · RHSA-2020:3841
Red Hat Enterprise Linux 6
jetty-eclipse
Not affected
Red Hat Enterprise Linux 7
jetty
Not affected
Red Hat JBoss Fuse 6
jetty
Not affected
Red Hat JBoss Fuse Service Works 6
jetty
Not affected
Red Hat Single Sign-On 7
jetty
Not affected
Red Hat Software Collections
rh-java-common-jetty
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7.8.0 | jetty | Fixed | RHSA-2020:5568 |
| Red Hat OpenShift Container Platform 3.11 | jenkins-0:2.235.5.1600415953-1.el7 | Fixed | RHSA-2020:4223 |
| Red Hat OpenShift Container Platform 4.3 | jenkins-0:2.235.5.1600415514-1.el7 | Fixed | RHSA-2020:3808 |
| Red Hat OpenShift Container Platform 4.4 | openshift4/ose-jenkins:v4.4.0-202009260441.p0 | Fixed | RHSA-2020:4220 |
| Red Hat OpenShift Container Platform 4.5 | jenkins-0:2.235.5.1600414805-1.el7 | Fixed | RHSA-2020:3841 |
| Red Hat Enterprise Linux 6 | jetty-eclipse | Not affected | n/a |
| Red Hat Enterprise Linux 7 | jetty | Not affected | n/a |
| Red Hat JBoss Fuse 6 | jetty | Not affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | jetty | Not affected | n/a |
| Red Hat Single Sign-On 7 | jetty | Not affected | n/a |
| Red Hat Software Collections | rh-java-common-jetty | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (39)
- http://www.openwall.com/lists/oss-security/2020/08/17/1 mailing-listx_refsource_MLIST
- https://access.redhat.com/security/cve/CVE-2019-17638 Vendor Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=564984 x_refsource_CONFIRMVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1864680 Issue Tracking
- https://github.com/advisories/GHSA-x3rh-m7vp-35f2 Advisory
- https://github.com/eclipse/jetty.project/commit/ff8ae56fa939c3477a0cdd1ff56ce3d902f08fba
- https://github.com/eclipse/jetty.project/issues/4936
- https://lists.apache.org/thread.html/r29073905dc9139d0d7a146595694bf57bb9e35e5ec6aa73eb9c8443a%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r29073905dc9139d0d7a146595694bf57bb9e35e5ec6aa73eb9c8443a@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r378e4cdec15e132575aa1dcb6296ffeff2a896745a8991522e266ad4%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r378e4cdec15e132575aa1dcb6296ffeff2a896745a8991522e266ad4@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r4bdd3f7bb6820a79f9416b6667d718a06d269018619a75ce4b759318%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r4bdd3f7bb6820a79f9416b6667d718a06d269018619a75ce4b759318@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r521168299e023fb075b57afe33d17ff1d09e8a10e0fd8c775ea0e028%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r521168299e023fb075b57afe33d17ff1d09e8a10e0fd8c775ea0e028@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r7fc5f2ed49641ea91c433e3cd0fc3d31c0278c87b82b15c33b881415%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r7fc5f2ed49641ea91c433e3cd0fc3d31c0278c87b82b15c33b881415@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r81f58591fb4716fb867b36956f30c7c8ad4ab3f23abc952d9d86a2a0%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r81f58591fb4716fb867b36956f30c7c8ad4ab3f23abc952d9d86a2a0@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r9584c4304c888f651d214341a939bd264ed30c9e3d0d30fe85097ecf%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9584c4304c888f651d214341a939bd264ed30c9e3d0d30fe85097ecf@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r9a2cfa56d30782a0c17a5deb951a622d1f5c8de48e1c3b578ffc2a84%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9a2cfa56d30782a0c17a5deb951a622d1f5c8de48e1c3b578ffc2a84@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/ra8661fc8c69c647cb06153c1485d48484a833d873f75dfe45937e9de%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/ra8661fc8c69c647cb06153c1485d48484a833d873f75dfe45937e9de@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/rbe1f230e87ea947593145d0072d0097ddb0af10fee1161db8ca1546c%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rbe1f230e87ea947593145d0072d0097ddb0af10fee1161db8ca1546c@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/rd98cfd012490cb02caa1a11aaa0cc38bff2d43bcce9b20c2f01063dd%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rd98cfd012490cb02caa1a11aaa0cc38bff2d43bcce9b20c2f01063dd@%3Ccommits.pulsar.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XE6US6VPZHOWFMUSFGDS5V2DNQPY5MKB/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XE6US6VPZHOWFMUSFGDS5V2DNQPY5MKB/
- https://nvd.nist.gov/vuln/detail/CVE-2019-17638
- https://snyk.io/vuln/SNYK-JAVA-ORGECLIPSEJETTY-575561
- https://www.cve.org/CVERecord?id=CVE-2019-17638
- https://www.jenkins.io/security/advisory/2020-08-17/
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISC
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISC
Change history (0)
No recorded changes yet.