Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-10241

Опубликовано: 22 апр. 2019
Источник: debian
EPSS Низкий

Описание

In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jetty9fixed9.4.18-1experimentalpackage
jetty9fixed9.4.18-2package
jetty8removedpackage
jetty8no-dsajessiepackage
jettyremovedpackage
jettynot-affectedjessiepackage

Примечания

  • https://bugs.eclipse.org/bugs/show_bug.cgi?id=546121

  • https://github.com/eclipse/jetty.project/issues/3319#issuecomment-567918620

EPSS

Процентиль: 93%
0.09686
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 7 лет назад

In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.

CVSS3: 4.7
redhat
почти 7 лет назад

In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.

CVSS3: 6.1
nvd
почти 7 лет назад

In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.

CVSS3: 6.1
github
почти 7 лет назад

Cross-site Scripting in Eclipse Jetty

CVSS3: 6.1
fstec
почти 7 лет назад

Уязвимость контейнера сервлетов Eclipse Jetty, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю провести XSS-атаки

EPSS

Процентиль: 93%
0.09686
Низкий