The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.
http://www.securitytracker.com/id/1031800
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151804.html
https://github.com/THU-HJY/CVE-Honeypot
https://github.com/6a6f6a6f/CVE-2015-2080
https://github.com/advisories/GHSA-ghgj-3xqr-6jfm
https://security.netapp.com/advisory/ntap-20190307-0005/
http://www.securityfocus.com/archive/1/534755/100/1600/threaded
http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00075.html
http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00074.html