CVE-2017-9735: Infoleak
Jetty could allow a remote attacker to obtain sensitive information, caused by a timing channel flaw in util/security/Password.java. By observing elapsed times before rejection of incorrect passwords, an attacker could exploit this vulnerability to obtain access information.
Other sources
Jetty through 9.4.x contains a timing channel attack in util/security/Password.java, which allows attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-9735?
CVE-2017-9735 is a vulnerability in Jetty that allows a remote attacker to obtain sensitive information.
What is the severity of CVE-2017-9735?
The severity of CVE-2017-9735 is high, with a severity value of 7.5.
What software is affected by CVE-2017-9735?
The following software versions are affected: Jetty 9.2.21.v20170120 to 9.2.22.v20170606, Jetty 9.3.0 to 9.3.20.v20170531, Jetty 9.4.0 to 9.4.6.v20170531, and Eclipse Jetty.
How can an attacker exploit CVE-2017-9735?
By observing elapsed times before rejection of incorrect passwords, an attacker can exploit this vulnerability to obtain access information.
Where can I find more information about CVE-2017-9735?
You can find more information about CVE-2017-9735 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-9735), [GitHub](https://github.com/eclipse/jetty.project/issues/1556), [Debian Bug Tracker](https://bugs.debian.org/864631).