Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-2080

Опубликовано: 24 фев. 2015
Источник: redhat
CVSS2: 5

Описание

The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.

Отчет

This issue did not affect the versions of jetty as shipped with Red Hat Enterprise Linux 7, versions of openshift-origin-cartridge-fuse as shipped with Red Hat OpenShift Enterprise 2.1, and versions of nutch as shipped with Red Hat Satellite 5.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7jettyNot affected
Red Hat OpenShift Enterprise 2openshift-origin-cartridge-fuseNot affected
Red Hat Satellite 5nutchNot affected

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1196254jetty: remote unauthenticated credential exposure

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.

CVSS3: 7.5
nvd
больше 9 лет назад

The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.

CVSS3: 7.5
debian
больше 9 лет назад

The exception handling code in Eclipse Jetty before 9.2.9.v20150224 al ...

CVSS3: 7.5
github
около 7 лет назад

Jetty vulnerable to exposure of sensitive information to unauthenticated remote users

5 Medium

CVSS2