CVE-2022-2191

HIGH

Eclipse Jetty <11.0.9 - Memory Corruption

Title source: llm
STIX 2.1

Description

In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.

Scores

CVSS v3 7.5
EPSS 0.0066
EPSS Percentile 71.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-664 CWE-404
Status published
Products (2)
eclipse/jetty 10.0.0 - 10.0.9
org.eclipse.jetty/jetty-server 10.0.0 - 10.0.10Maven
Published Jul 07, 2022
Tracked Since Feb 18, 2026