Jetty vulnerable to exposure of sensitive information due to observable discrepancy
High severity
GitHub Reviewed
Published
Oct 19, 2018
to the GitHub Advisory Database
•
Updated Aug 15, 2023
Package
Affected versions
>= 9.4.0, <= 9.4.5.v20170502
>= 9.3.0, <= 9.3.19.v20170502
<= 9.2.21.v20170120
Patched versions
9.4.6.v20170531
9.3.20.v20170531
9.2.22.v20170606
Description
Published by the National Vulnerability Database
Jun 16, 2017
Published to the GitHub Advisory Database
Oct 19, 2018
Reviewed
Jun 16, 2020
Last updated
Aug 15, 2023
Jetty through 9.4.x contains a timing channel attack in
util/security/Password.java
, which allows attackers to obtain access by observing elapsed times before rejection of incorrect passwords.References