The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.
http://www.securitytracker.com/id/1031800
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151804.html
https://security.netapp.com/advisory/ntap-20190307-0005/
http://www.securityfocus.com/archive/1/534755/100/1600/threaded
http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00075.html
http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00074.html
Source: Mitre, NVD
Published: 2016-10-07
Updated: 2025-04-12
Base Score: 5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
Severity: Medium
Base Score: 7.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity: High
EPSS: 0.91469