Back to Database
Status published
High
CVE-2017-9735
Jetty through 9.4.x is prone to a timing channel in...
Vulnerability Description
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-9735
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/99104
- https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
- https://lists.apache.org/thread.html/36870f6c51f5bc25e6f7bb1fcace0e57e81f1524019b11f466738559%40%3Ccommon-dev.hadoop.apache.org%3E
- https://lists.apache.org/thread.html/f887a5978f5e4c62b9cfe876336628385cff429e796962649649ec8a%40%3Ccommon-issues.hadoop.apache.org%3E
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://bugs.debian.org/864631
- https://github.com/eclipse/jetty.project/issues/1556
- https://lists.debian.org/debian-lts-announce/2021/05/msg00016.html
- https://www.oracle.com//security-alerts/cpujul2021.html
More from eclipse
View All →CVE-2023-41900
Jetty's OpenId Revoked authentication allows one request
Low
3.5
CVE-2023-40167
Jetty accepts "+" prefixed value in Content-Length
Medium
5.3
CVE-2023-36479
Jetty vulnerable to errant command quoting in CGI Servlet
Low
3.5
CVE-2023-36478
HTTP/2 HPACK integer overflow and buffer allocation
High
7.5
CVE-2023-26049
Cookie parsing of quoted values can exfiltrate values from other cookies in Eclipse Jetty
Low
2.4
Affected Vendor
eclipse
View all reports →Affected Software
jetty, debian linux, communications cloud native core policy, enterprise manager base platform, hospitality guest access, rest data services, retail xstore point of service
Vulnerable Versions:
0, 9.3.0, 9.4.0, 9.0, 1.5.0, 13.2, 13.3, 4.2.0, 4.2.1, 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, 7.1, 15.0, 16.0, 17.0
Timeline
Official Publish:
June 16th, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.