Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10246

Опубликовано: 15 апр. 2019
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

A flaw was found in Eclipse Jetty. This issue may lead to exposure of the fully qualified Base Resource directory name on Windows to a remote client when configured to show a listing of directory contents. By sending a specially-crafted request, a remote attacker could obtain sensitive information.

Отчет

This CVE only impacts users using Eclipse Jetty on Windows.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7jettyNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-538
https://bugzilla.redhat.com/show_bug.cgi?id=2187703jetty: Directory Listing on Windows reveals Resource Base path

EPSS

Процентиль: 90%
0.04016
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

CVSS3: 5.3
nvd
больше 7 лет назад

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

CVSS3: 5.3
debian
больше 7 лет назад

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server runnin ...

CVSS3: 5.3
github
больше 7 лет назад

Information Exposure vulnerability in Eclipse Jetty

CVSS3: 5.3
fstec
больше 7 лет назад

Уязвимость контейнера сервлетов Eclipse Jetty, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 90%
0.04016
Низкий

5.3 Medium

CVSS3