CVE-2015-2080: Eclipse Jetty
High severity, CVSS 7.5. EPSS: 75.4% chance of exploitation in the next 30 days.
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.
Affected products
- Eclipse Jetty: version 9.2.3 only; version 9.2.4 only; version 9.2.5 only; version 9.2.6 only; version 9.2.7 only; version 9.2.8 only; …
- Fedoraproject Fedora: version 22 only
Published 2016-10-07. Last modified 2026-06-17.