CVE-2017-9735: Infoleak
Jetty through 9.4.x contains a timing channel attack in util/security/Password.java, which allows attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
Other sources
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.eclipse.jetty:jetty-serverto a version that resolves this vulnerability.Fixed in 9.2.22.v20170606 - Upgrade
Upgrade
maven/org.eclipse.jetty:jetty-serverto a version that resolves this vulnerability.Fixed in 9.3.20.v20170531 - Upgrade
Upgrade
maven/org.eclipse.jetty:jetty-serverto a version that resolves this vulnerability.Fixed in 9.4.6.v20170531
Event History
Frequently Asked Questions
What is CVE-2017-9735?
CVE-2017-9735 is a vulnerability in Jetty that allows a remote attacker to obtain sensitive information.
What is the severity of CVE-2017-9735?
The severity of CVE-2017-9735 is high, with a severity value of 7.5.
What software is affected by CVE-2017-9735?
The following software versions are affected: Jetty 9.2.21.v20170120 to 9.2.22.v20170606, Jetty 9.3.0 to 9.3.20.v20170531, Jetty 9.4.0 to 9.4.6.v20170531, and Eclipse Jetty.
How can an attacker exploit CVE-2017-9735?
By observing elapsed times before rejection of incorrect passwords, an attacker can exploit this vulnerability to obtain access information.
Where can I find more information about CVE-2017-9735?
You can find more information about CVE-2017-9735 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-9735), [GitHub](https://github.com/eclipse/jetty.project/issues/1556), [Debian Bug Tracker](https://bugs.debian.org/864631).