MGASA-2017-0277

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 18 Aug 2017, 17:06
Last modified:16 Apr 2026, 06:23

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Aug 2017, 17:06
Published
Vulnerability first disclosed
16 Apr 2026, 06:23
Last Modified
Vulnerability information updated

Description

Updated jetty packages fix security vulnerability Jetty is prone to a timing channel attack in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords (CVE-2017-9735).

Affected Systems

  • mageiajetty

    < 9.4.6-1.v20170531.1.1.mga6

  • mageiajetty-alpn

    < 8.1.11-3.v20170118.1.mga6

  • mageiajetty-test-helper

    < 3.1-4.mga6

References (3)