CVE-2017-9735
Jetty vulnerable to exposure of sensitive information due to observable discrepancy
Description
Jetty through 9.4.x contains a timing channel attack in util/security/Password.java
, which allows attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
Base CVSS
7.5
EPSS Score
0.64%
Introduced Version
7.0.0.M0
Fix Available
9.2.22.v20170606,9.3.20.v20170531,9.4.6.v20170531
Available Patches
Package
CVEs Fixed
Lines of Code Changed