Description
In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.
Remediation
References
Related Vulnerabilities
WordPress Plugin Role Scoper Cross-Site Scripting (1.3.66)
WordPress Plugin WordPress-Amazon-Associate (WPAA) Cross-Site Scripting (2.0)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-3221)
concrete5 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-5107)