CVE-2015-2080

high
Published 2016-10-07 · Modified 2024-02-16
CVSS v3
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2
5.0
VIR risk
7.5

Description

Jetty vulnerable to exposure of sensitive information to unauthenticated remote users

Predictions

Exploit likelihood
83%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/eclipse/jetty.project/blob/jetty-9.2.x/advisories/2015-02-24-httpparser-error-buffer-bleed.md

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00075.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00074.html

OS impact

OSVersionStatusFixed in
fedora fedora22affected

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.eclipse.jetty:jetty-server<9.2.9.v201502249.2.9.v20150224

Application impact

VendorProductVersionsFixed
eclipsejetty9.2.3
eclipsejetty9.2.4
eclipsejetty9.2.5
eclipsejetty9.2.6
eclipsejetty9.2.7
eclipsejetty9.2.8
eclipsejetty9.3.0

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.