Description
In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2661-1 | jetty9 security update |
Debian DSA |
DSA-4949-1 | jetty9 security update |
Github GHSA |
GHSA-7vx9-xjhr-rw6h | Cross-site Scripting in Eclipse Jetty |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Apache
Subscribe
Activemq
Subscribe
Drill
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Eclipse
Subscribe
Jetty
Subscribe
Oracle
Subscribe
Flexcube Core Banking
Subscribe
Rest Data Services
Subscribe
Retail Xstore Point Of Service
Subscribe
Redhat
Subscribe
Amq Broker
Subscribe
Jboss Fuse
Subscribe
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-04T22:17:19.587Z
Reserved: 2019-03-27T00:00:00.000Z
Link: CVE-2019-10241
No data.
Status : Modified
Published: 2019-04-22T20:29:00.243
Modified: 2024-11-21T04:18:43.417
Link: CVE-2019-10241
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Github GHSA