Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.eclipse.jetty/jetty-server
  4. ›
  5. CVE-2022-2191

CVE-2022-2191: Improper Resource Shutdown or Release

July 7, 2022 (updated September 23, 2022)

In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.

References

  • github.com/eclipse/jetty.project/security/advisories/GHSA-8mpp-f3f7-xc28
  • nvd.nist.gov/vuln/detail/CVE-2022-2191

Code Behaviors & Features

Detect and mitigate CVE-2022-2191 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 10.0.0 up to 10.0.9, all versions starting from 11.0.0 up to 11.0.9

Solution

Unfortunately, there is no solution available yet.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-404: Improper Resource Shutdown or Release

Source file

maven/org.eclipse.jetty/jetty-server/CVE-2022-2191.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:53 +0000.