CVE-2017-9735

Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:jetty:*:20170531:*:*:*:*:*:*

Information

Published : 2017-06-16 21:29

Updated : 2021-07-20 23:15


NVD link : CVE-2017-9735

Mitre link : CVE-2017-9735


JSON object : View

Products Affected

eclipse

  • jetty
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor