An open index of dependabot pull requests across open source projects.

Jetty vulnerable to exposure of sensitive information due to observable discrepancy

GHSA-wfcc-pff6-rgc5 CVE-2017-9735
Description:

Jetty through 9.4.x contains a timing channel attack in util/security/Password.java, which allows attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

Affected Packages
Ecosystem Package Vulnerable Versions Patched Version
maven org.eclipse.jetty:jetty-server <= 9.2.21.v20170120
>= 9.3.0, <= 9.3.19.v20170502
>= 9.4.0, <= 9.4.5.v20170502
9.2.22.v20170606
Related Dependabot Pull Requests
Advisory Details
Published: October 19, 2018 over 7 years ago
Updated: June 09, 2026 6 days ago
CVSS Score: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.71% 73th percentile
Source: Github
Classification: GENERAL
UUID: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdmY2MtcGZmNi1yZ2M1