CVE-2015-2080 has been assigned to this issue in which Jetty sends an HTTP response to one client containing HTTP request data from a different client: External References: http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00074.html Statement: This issue did not affect the versions of jetty as shipped with Red Hat Enterprise Linux 7, versions of openshift-origin-cartridge-fuse as shipped with Red Hat OpenShift Enterprise 2.1, and versions of nutch as shipped with Red Hat Satellite 5.
Victims Record: https://github.com/victims/victims-cve-db/blob/master/database/java/2015/2080.yaml
Upstream Fix: https://github.com/eclipse/jetty.project/commit/3e7b5f0fa918633ec24bd1bc23d6ee76d32c7729 https://github.com/eclipse/jetty.project/commit/4df5647f6dfdc5fa7abb812afe9290d60b17c098
jetty-9.2.9-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.