Miggo Logo

CVE-2017-9735: Jetty vulnerable to exposure of sensitive information due to observable discrepancy

7.5

CVSS Score
3.1

Basic Information

EPSS Score
0.69593%
Published
10/19/2018
Updated
8/15/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.eclipse.jetty:jetty-servermaven>= 9.4.0, <= 9.4.5.v201705029.4.6.v20170531
org.eclipse.jetty:jetty-servermaven>= 9.3.0, <= 9.3.19.v201705029.3.20.v20170531
org.eclipse.jetty:jetty-servermaven<= 9.2.21.v201701209.2.22.v20170606

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

J*tty t*rou** *.*.x *ont*ins * timin* ***nn*l *tt**k in `util/s**urity/P*sswor*.j*v*`, w*i** *llows *tt**k*rs to o*t*in ****ss *y o*s*rvin* *l*ps** tim*s ***or* r*j**tion o* in*orr**t p*sswor*s.

Reasoning

No *n*lysis *v*il**l*