CVE-2019-17638 is a critical vulnerability affecting Eclipse Jetty versions 9.4.27.v20200227 to 9.4.29.v20200521. It arises from a double-free error in the ByteBufferPool when handling oversized response headers, leading to two threads acquiring the same buffer. This allows sensitive data from one client's request (e.g., session IDs, credentials) to be inadvertently sent to another client. With a CVSS score of 9.4 (CRITICAL), it is a network-exploitable vulnerability with low attack complexity, posing a high risk of confidentiality and integrity compromise, and a low impact on availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.4.27CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:9.4.27:20200227:*:*:*:*:*:* | ||
9.4.28CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:9.4.28:20200408:*:*:*:*:*:* | ||
9.4.29CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:9.4.29:20200521:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.