原始 OSV JSON{
"id": "GHSA-ghgj-3xqr-6jfm",
"aliases": [
"CVE-2015-2080"
],
"details": "The exception handling code in Eclipse Jetty prior to 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.",
"summary": "Jetty vulnerable to exposure of sensitive information to unauthenticated remote users",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "9.2.9.v20150224"
}
]
}
],
"package": {
"name": "org.eclipse.jetty:jetty-server",
"ecosystem": "Maven"
},
"database_specific": {
"last_known_affected_version_range": "<= 9.2.8.v20150217"
}
}
],
"modified": "2022-09-14T01:06:27Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"published": "2018-11-09T17:50:00Z",
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2015-2080",
"type": "ADVISORY"
},
{
"url": "https://blog.gdssecurity.com/labs/2015/2/25/jetleak-vulnerability-remote-leakage-of-shared-buffers-in-je.html",
"type": "WEB"
},
{
"url": "https://github.com/advisories/GHSA-ghgj-3xqr-6jfm",
"type": "ADVISORY"
},
{
"url": "https://github.com/eclipse/jetty.project/blob/jetty-9.2.x/advisories/2015-02-24-httpparser-error-buffer-bleed.md",
"type": "WEB"
},
{
"url": "https://security.netapp.com/advisory/ntap-20190307-0005",
"type": "WEB"
},
{
"url": "http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00074.html",
"type": "WEB"
},
{
"url": "http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00075.html",
"type": "WEB"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151804.html",
"type": "WEB"
},
{
"url": "http://packetstormsecurity.com/files/130567/Jetty-9.2.8-Shared-Buffer-Leakage.html",
"type": "WEB"
},
{
"url": "http://seclists.org/fulldisclosure/2015/Mar/12",
"type": "WEB"
},
{
"url": "http://www.securityfocus.com/archive/1/534755/100/1600/threaded",
"type": "WEB"
},
{
"url": "http://www.securityfocus.com/bid/72768",
"type": "WEB"
},
{
"url": "http://www.securitytracker.com/id/1031800",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "HIGH",
"github_reviewed": true,
"nvd_published_at": null,
"github_reviewed_at": "2020-06-16T21:37:23Z"
}
}