Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2017-06-16 14:29
Updated : 2022-03-15 07:55
NVD link : CVE-2017-9735
Mitre link : CVE-2017-9735
JSON object : View
CWE
CWE-203
Observable Discrepancy
Products Affected
oracle
- rest_data_services
- enterprise_manager_base_platform
- retail_xstore_point_of_service
- hospitality_guest_access
- communications_cloud_native_core_policy
eclipse
- jetty
debian
- debian_linux