Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wfcc-pff6-rgc5

Опубликовано: 19 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Jetty vulnerable to exposure of sensitive information due to observable discrepancy

Jetty through 9.4.x contains a timing channel attack in util/security/Password.java, which allows attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

Пакеты

Наименование

org.eclipse.jetty:jetty-server

maven
Затронутые версииВерсия исправления

>= 9.4.0, <= 9.4.5.v20170502

9.4.6.v20170531

Наименование

org.eclipse.jetty:jetty-server

maven
Затронутые версииВерсия исправления

>= 9.3.0, <= 9.3.19.v20170502

9.3.20.v20170531

Наименование

org.eclipse.jetty:jetty-server

maven
Затронутые версииВерсия исправления

<= 9.2.21.v20170120

9.2.22.v20170606

EPSS

Процентиль: 74%
0.00844
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-203

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

CVSS3: 5.1
redhat
больше 8 лет назад

Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

CVSS3: 7.5
nvd
больше 8 лет назад

Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

CVSS3: 7.5
debian
больше 8 лет назад

Jetty through 9.4.x is prone to a timing channel in util/security/Pass ...

EPSS

Процентиль: 74%
0.00844
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-203