The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.
https://security.netapp.com/advisory/ntap-20190307-0005/
http://www.securitytracker.com/id/1031800
http://www.securityfocus.com/archive/1/534755/100/1600/threaded
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151804.html
http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00075.html
http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00074.html