Thursday, July 9, 2020

New vulnerability on the NVD: CVE-2019-17638



In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP response headers is released back to the ByteBufferPool twice.

from Pocket https://ift.tt/2W5I0YT
via IFTTT

No comments:

Post a Comment