PT-2017-19144 · Eclipse+2 · Jetty+2
Published
2017-06-16
·
Updated
2022-03-15
·
CVE-2017-9735
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jetty versions prior to 9.4.x
Description
The issue is related to a timing channel in
util/security/Password.java, which allows remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords. This makes it easier for attackers to gain unauthorized access.Recommendations
For Jetty versions prior to 9.4.x, consider disabling the
Password.java functionality until a patch is available. Restrict access to the util/security/Password.java module to minimize the risk of exploitation. Avoid using the Password.java function for password verification until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Information Disclosure
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Jetty
Jira