Security readout for executives and security teams
Affected Eclipse Jetty versions can accidentally send one user's response data to another user when oversized response headers trigger an error path. The exposed data could include session IDs or authentication credentials. This is primarily a confidentiality issue, with business urgency highest for multi-user web services running the affected Jetty range. Exposure is likely where applications, platforms, or packaged products embed Eclipse Jetty 9.4.27.v20200227 through 9.4.29.v20200521. Public references include downstream package and project discussions, so validate both direct Jetty deployments and transitive dependencies. Patch or mitigate confirmed affected Jetty services promptly, especially customer-facing or shared applications. This is not evidenced as actively exploited in the supplied sources, but the potential leakage of credentials and session data makes delayed remediation risky. Mitigation focus: Upgrade Eclipse Jetty outside the affected 9.4.27 to 9.4.29 range.; If upgrade is blocked, check current vendor guidance for supported mitigation.; Set responseHeaderSize significantly larger than requestHeaderSize where vendor guidance allows..
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-672: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCWE-675: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2019-17638 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=564984CVE reference · x_refsource_CONFIRM
- FEDORA-2020-cf8ef2f333CVE reference · vendor-advisory, x_refsource_FEDORA
- [pulsar-commits] 20200903 [GitHub] [pulsar] guyv opened a new issue #7970: pulsar-client vulnerability CVE-2019-17638CVE reference · mailing-list, x_refsource_MLIST
- [pulsar-commits] 20200911 [GitHub] [pulsar] codelipenghui closed issue #7970: pulsar-client vulnerability CVE-2019-17638CVE reference · mailing-list, x_refsource_MLIST
- [pulsar-commits] 20200912 [GitHub] [pulsar] codelipenghui closed issue #7970: pulsar-client vulnerability CVE-2019-17638CVE reference · mailing-list, x_refsource_MLIST
- [pulsar-commits] 20200914 [GitHub] [pulsar] klwilson227 opened a new issue #8060: CVE-2019-17638 jetty serverCVE reference · mailing-list, x_refsource_MLIST
- [pulsar-commits] 20200922 [GitHub] [pulsar] zymap commented on issue #8060: CVE-2019-17638 jetty serverCVE reference · mailing-list, x_refsource_MLIST
- [pulsar-commits] 20200923 [GitHub] [pulsar] zymap commented on issue #8060: CVE-2019-17638 jetty serverCVE reference · mailing-list, x_refsource_MLIST
- [pulsar-commits] 20200929 [GitHub] [pulsar] sijie closed issue #8060: CVE-2019-17638 jetty serverCVE reference · mailing-list, x_refsource_MLIST
- [pulsar-commits] 20200929 [GitHub] [pulsar] sijie commented on issue #8060: CVE-2019-17638 jetty serverCVE reference · mailing-list, x_refsource_MLIST
- [pulsar-commits] 20201005 [GitHub] [pulsar] abhishekheaven7 opened a new issue #8203: Pulsar client with version 2.6.1 has critical vulnerability CVE-2019-17638CVE reference · mailing-list, x_refsource_MLIST
- [pulsar-commits] 20201005 [GitHub] [pulsar] abhishekheaven7 closed issue #8203: Pulsar client with version 2.6.1 has critical vulnerability CVE-2019-17638CVE reference · mailing-list, x_refsource_MLIST
- https://www.oracle.com/security-alerts/cpuoct2020.htmlCVE reference · x_refsource_MISC
- [pulsar-commits] 20201215 [GitHub] [pulsar] yanshuchong opened a new issue #8967: CVSS issue listCVE reference · mailing-list, x_refsource_MLIST
- [pulsar-commits] 20210127 [GitHub] [pulsar] GLouMcK opened a new issue #9347: Security Vulnerabilities - Black Duck ScanCVE reference · mailing-list, x_refsource_MLIST
- https://www.oracle.com/security-alerts/cpuApr2021.htmlCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Operation on a Resource after Expiration or Release
Operation on a Resource after Expiration or Release represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
Multiple Operations on Resource in Single-Operation Context
Multiple Operations on Resource in Single-Operation Context represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
