Eclipse Jetty Web Server 400 Response Information Disclosure

Strike ID:
E15-4ls01
CVSS:
7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
False Positive:
f
Variants:
960
Year:
2015

Description

This strike exploits an information disclosure vulnerability in Eclipse Jetty Web Server versions prior to 9.2.9.v20150224. The vulnerability exists due to improper treatment of HTTP request parsing. Successful exploitation will result in disclosure of information related to previous HTTP requests sent to the server.

CVE

References

Bid