Description
For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected products
- Eclipse / jetty10.0.7 – 10.0.23
- Eclipse Foundation / Eclipse Jetty10.0.7 – 10.0.23
- Eclipse Foundation / Eclipse Jetty11.0.7 – 11.0.23
Updated 16m ago · 8 sources