The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.
| Software | From | Fixed in |
|---|---|---|
| fedoraproject / fedora | 22 | 22.x |
| eclipse / jetty | 9.3.0-m0 | 9.3.0-m0.x |
| eclipse / jetty | 9.2.5 | 9.2.5.x |
| eclipse / jetty | 9.2.4 | 9.2.4.x |
| eclipse / jetty | 9.2.8 | 9.2.8.x |
| eclipse / jetty | 9.3.0-m1 | 9.3.0-m1.x |
| eclipse / jetty | 9.2.7 | 9.2.7.x |
| eclipse / jetty | 9.2.3 | 9.2.3.x |
| eclipse / jetty | 9.2.6 | 9.2.6.x |
org.eclipse.jetty / jetty-server
|
- | 9.2.9.v20150224 |