CVE Published: 07/07/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: eclipse |
Vendor: The Eclipse Foundation |
Product: Eclipse Jetty Status : PUBLISHED
CVE-2022-2191 Description
In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H