Description
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
Remediation
References
Related Vulnerabilities
WordPress Plugin Easy PayPal Buy Now Button Cross-Site Scripting (1.7.3)
WordPress Plugin WP Visitor Statistics (Real Time Traffic) SQL Injection (5.7)
WordPress Plugin Integration for Contact Form 7 and Constant Contact Cross-Site Scripting (1.0.8)
RubyGems Origin Validation Error Vulnerability (CVE-2017-0902)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-9276)