Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-2080

78
FAUCET Score

CVE-2015-2080, known as JetLeak, is a sensitive information disclosure vulnerability affecting Eclipse Jetty versions prior to 9.2.9.v20150224, including those used in Fedora. This flaw allows remote attackers to extract data from process memory by sending HTTP headers with illegal characters, due to improper exception handling. The vulnerability carries a high CVSSv3 score of 7.5, indicating a critical risk. It is easily exploitable over the network with low complexity and no user interaction, leading to a high impact on confidentiality. While not listed on the KEV catalog, exploit intelligence shows available Nuclei templates and an ExploitDB entry (EDB-39455) for a related product. The vulnerability has garnered significant community discussion and media coverage, suggesting awareness and potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
22CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
9.2.3CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:9.2.3:*:*:*:*:*:*:*
9.2.4CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:9.2.4:*:*:*:*:*:*:*
9.2.5CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:9.2.5:*:*:*:*:*:*:*
9.2.6CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:9.2.6:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
74.88%
Probability of exploitation in next 30 days
EPSS Percentile
99.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2015-2080 · Mar 6, 2021
ExploitDB: EDB-39455 · Feb 17, 2016
This CVE's current EPSS score of 0.7488 is in the 99th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

mavenpatch availablevia ghsa
Product: org.eclipse.jetty:jetty-serverFixed in: 9.2.9.v20150224
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

mavenGHSA-ghgj-3xqr-6jfmhigh

Jetty vulnerable to exposure of sensitive information to unauthenticated remote users

Nov 9, 2018
redhatCVE-2015-2080Important

jetty: remote unauthenticated credential exposure

Feb 24, 2015

References

dev.eclipse.org / mhonarc/lists/jetty-announce/msg00074.html
Vendor Advisory
dev.eclipse.org / mhonarc/lists/jetty-announce/msg00075.html
Vendor Advisory
lists.fedoraproject.org / pipermail/package-announce/2015-March/151804.html
Third Party Advisory
packetstormsecurity.com / files/130567/Jetty-9.2.8-Shared-Buffer-Leakage.html
ExploitThird Party Advisory
blog.gdssecurity.com / labs/2015/2/25/jetleak-vulnerability-remote-leakage-of-shared-buffers-in-je.html
ExploitThird Party Advisory
seclists.org / fulldisclosure/2015/Mar/12
ExploitThird Party Advisory
github.com / eclipse/jetty.project/blob/jetty-9.2.x/advisories/2015-02-24-httpparser-error-buffer-bleed.md
ExploitVendor Advisory
security.netapp.com / advisory/ntap-20190307-0005
securityfocus.com / archive/1/534755/100/1600/threaded
securityfocus.com / bid/72768
Broken Link
securitytracker.com / id/1031800
Third Party Advisory