Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-17632

Опубликовано: 25 нояб. 2019
Источник: redhat
CVSS3: 6.1

Описание

In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6jetty-eclipseNot affected
Red Hat Enterprise Linux 7jettyNot affected
Red Hat Fuse 7jettyNot affected
Red Hat JBoss Fuse 6jettyOut of support scope
Red Hat JBoss Fuse Service Works 6jettyOut of support scope
Red Hat Satellite 5nutchOut of support scope
Red Hat Single Sign-On 7jettyNot affected
Red Hat Software Collectionsrh-java-common-jettyNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1781214jetty: generation of default unhandled error response content does not escape exception messages in stacktraces included in error output

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.

CVSS3: 6.1
nvd
около 6 лет назад

In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.

CVSS3: 6.1
debian
около 6 лет назад

In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4. ...

CVSS3: 6.1
github
около 6 лет назад

Unescaped exception messages in error responses in Jetty

6.1 Medium

CVSS3