ZeroHour

CVE-2022-2191

PoC
CVSS 3.1
7.5 high
EPSS
2%p82
Published
()
Modified
Description

In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.

Vendors
eclipse
Products
jetty
Weakness
CWE-404, CWE-664
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.