Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2017-06-16 21:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-9735
Mitre link : CVE-2017-9735
CVE.ORG link : CVE-2017-9735
JSON object : View
Products Affected
debian
- debian_linux
oracle
- communications_cloud_native_core_policy
- enterprise_manager_base_platform
- rest_data_services
- hospitality_guest_access
- retail_xstore_point_of_service
eclipse
- jetty
CWE
CWE-203
Observable Discrepancy