PoC Index

CVE-2015-2080

HIGH 7.5EPSS 74.9%

The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.

CVSS v3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
74.88% chance of exploitation in the next 30 days, 99th percentile
Nuclei
high · CWE-200
Published
2016-10-07
Updated
2024-08-06

Proof-of-concept exploits (3)

Nuclei templates (1)

ExploitDB entries (1)

References

Related