Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-17632

Опубликовано: 25 нояб. 2019
Источник: debian

Описание

In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jetty9fixed9.4.26-1package
jetty9not-affectedbusterpackage
jetty9not-affectedstretchpackage
jetty8removedpackage
jetty8not-affectedjessiepackage
jettyremovedpackage
jettynot-affectedjessiepackage

Примечания

  • https://bugs.eclipse.org/bugs/show_bug.cgi?id=553443

  • https://github.com/eclipse/jetty.project/issues/4334

  • Introduced by https://github.com/eclipse/jetty.project/commit/bde86467f4e5df595773ab11ed5e80c615b741f3 (jetty-9.4.21.v20190926)

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.

CVSS3: 6.1
redhat
около 6 лет назад

In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.

CVSS3: 6.1
nvd
около 6 лет назад

In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.

CVSS3: 6.1
github
около 6 лет назад

Unescaped exception messages in error responses in Jetty