Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-10246

Опубликовано: 22 апр. 2019
Источник: debian
EPSS Низкий

Описание

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jetty9not-affectedpackage
jetty8not-affectedpackage
jettynot-affectedpackage

Примечания

  • https://bugs.eclipse.org/bugs/show_bug.cgi?id=546576

  • https://github.com/eclipse/jetty.project/issues/3549

EPSS

Процентиль: 85%
0.02625
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 7 лет назад

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

CVSS3: 5.3
redhat
почти 7 лет назад

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

CVSS3: 5.3
nvd
почти 7 лет назад

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

CVSS3: 5.3
github
почти 7 лет назад

Information Exposure vulnerability in Eclipse Jetty

CVSS3: 5.3
fstec
почти 7 лет назад

Уязвимость контейнера сервлетов Eclipse Jetty, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 85%
0.02625
Низкий