CVE-2015-2080, known as JetLeak, is a sensitive information disclosure vulnerability affecting Eclipse Jetty versions prior to 9.2.9.v20150224, including those used in Fedora. This flaw allows remote attackers to extract data from process memory by sending HTTP headers with illegal characters, due to improper exception handling. The vulnerability carries a high CVSSv3 score of 7.5, indicating a critical risk. It is easily exploitable over the network with low complexity and no user interaction, leading to a high impact on confidentiality. While not listed on the KEV catalog, exploit intelligence shows available Nuclei templates and an ExploitDB entry (EDB-39455) for a related product. The vulnerability has garnered significant community discussion and media coverage, suggesting awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
22CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:* | ||
9.2.3CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:9.2.3:*:*:*:*:*:*:* | ||
9.2.4CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:9.2.4:*:*:*:*:*:*:* | ||
9.2.5CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:9.2.5:*:*:*:*:*:*:* | ||
9.2.6CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:9.2.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.