CVE-2017-9735
—CVSS 3.1
7.5 high
EPSS
6%p93
Published
()
Modified
Description
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
In the news0 stories
No ingested article mentions this CVE yet.