CVE-2019-17638

CWE-672CWE-675CWE-134112 documents9 sources
Severity
9.4CRITICAL
EPSS
30.9%
top 3.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 9
Latest updateApr 15

Description

In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP response headers is released back to the ByteBufferPool twice. Because of this double release, two threads can acquire the same ByteBuffer from the pool and while thread1 is about to use the ByteBuffer to write response1 data, thread2 fills the ByteBuffer with other data. Thread1 then

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LExploitability: 3.9 | Impact: 5.5

Affected Packages4 packages

Mavenorg.eclipse.jetty:jetty-server9.4.279.4.30.v20200611
NVDeclipse/jetty9.4.27, 9.4.28, 9.4.29+2
CVEListV5the_eclipse_foundation/eclipse_jetty9.4.27.v20200227 to 9.4.29.v20200521
Debianjetty9< 9.4.31-1+3

🔴Vulnerability Details

4
GHSA
Operation on a Resource after Expiration or Release in Jetty Server2020-08-05
OSV
Operation on a Resource after Expiration or Release in Jetty Server2020-08-05
CVEList
CVE-2019-17638: In Eclipse Jetty, versions 92020-07-09
OSV
CVE-2019-17638: In Eclipse Jetty, versions 92020-07-09

📋Vendor Advisories

5
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Demographics (Eclipse Jetty) — CVE-2019-176382021-04-15
Oracle
Oracle Oracle Communications Risk Matrix: WS and WEB (Eclipse Jetty) — CVE-2019-176382020-10-15
Jenkins
Jenkins Security Advisory 2020-08-172020-08-17
Red Hat
jetty: double release of resource can lead to information disclosure2020-06-03
Debian
CVE-2019-17638: jetty9 - In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too ...2019

💬Community

2
Bugzilla
CVE-2019-17638 jetty: double release of resource can lead to information disclosure [fedora-all]2020-08-03
Bugzilla
CVE-2019-17638 jetty: double release of resource can lead to information disclosure2020-08-03