Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r28m-g6j9-r2h5

Опубликовано: 23 апр. 2019
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Information Exposure vulnerability in Eclipse Jetty

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

Пакеты

Наименование

org.eclipse.jetty:jetty-server

maven
Затронутые версииВерсия исправления

>= 9.2.0, <= 9.2.27.v20190403

9.2.28.v20190418

Наименование

org.eclipse.jetty:jetty-server

maven
Затронутые версииВерсия исправления

>= 9.3.0, <= 9.3.26.v20190403

9.3.27.v20190418

Наименование

org.eclipse.jetty:jetty-server

maven
Затронутые версииВерсия исправления

>= 9.4.0, <= 9.4.16.v20190411

9.4.17.v20190418

EPSS

Процентиль: 85%
0.02625
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-213

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 7 лет назад

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

CVSS3: 5.3
redhat
почти 7 лет назад

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

CVSS3: 5.3
nvd
почти 7 лет назад

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

CVSS3: 5.3
debian
почти 7 лет назад

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server runnin ...

CVSS3: 5.3
fstec
почти 7 лет назад

Уязвимость контейнера сервлетов Eclipse Jetty, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 85%
0.02625
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-213