Mageni can help you to save time and money
Mageni automates for you the vulnerability scanning, assessment and management process saving you a ton of time, resources, and money. Mageni is used by companies of all sizes. You will love Mageni's powerful features and ease of use. No registration or credit card is required.
Download Now
Eclipse Jetty Vulnerability - CVE-2019-17638 (Linux)
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
Eclipse Jetty is prone to a vulnerability where sensitive information about clients could be obtained.
Insight
Insight
In case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP response headers is released back to the ByteBufferPool twice. Because of this double release, two threads can acquire the same ByteBuffer from the pool and while thread1 is about to use the ByteBuffer to write response1 data, thread2 fills the ByteBuffer with response2 data. Thread1 then proceeds to write the buffer that now contains response2 data. This results in client1, which issued request1 and expects responses, to see response2 which could contain sensitive data belonging to client2 (HTTP session ids, authentication credentials, etc.).
Affected Software
Affected Software
Eclipse Jetty version 9.4.27.v20200227 to 9.4.29.v20200521.
Detection Method
Detection Method
Checks if a vulnerable version is present on the target host.
Solution
Solution
No known solution is available as of 15th July, 2020. Information regarding this issue will be updated once solution details are available.
Common Vulnerabilities and Exposures (CVE)
Automate with a few clicks your vulnerability scanning, assessment and management process
Automate with a few clicks your vulnerability scanning, assessment and management process
Mageni automates for you the vulnerability scanning, assessment and management process saving you a ton of time, resources, and money. No registration or credit card is required. Mageni Community Edition is fast, powerful, free, and open-source. Download it now and Mageni will find your vulnerabilities before they are exploited by hackers.
1. Download Multipass
2. Launch a multipass instance
3. Install Mageni
1. If you don’t have it already, install Brew. Then, to install Multipass simply execute:
2. Launch a multipass instance
2. Install Mageni
1. Download the installer for Windows
2. Ensure your network is private
3. Run the installer
4. Launch a multipass instance
5. Log into the multipass instance
6. Install Mageni