PT-2019-3890 · Eclipse+1 · Eclipse Jetty+1

Publicado

2019-04-04

·

Atualizado

2022-12-24

·

CVE-2019-10241

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Jetty versions 9.2.26 and older Eclipse Jetty versions 9.3.25 and older Eclipse Jetty versions 9.4.15 and older
Description The server is vulnerable to XSS conditions if a remote client uses a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a listing of directory contents. This issue arises due to the lack of protection for the web page structure, allowing a remote attacker to conduct XSS attacks by using a specially formatted URL.
Recommendations For Eclipse Jetty versions 9.2.26 and older, update to a version newer than 9.2.26 to resolve the issue. For Eclipse Jetty versions 9.3.25 and older, update to a version newer than 9.3.25 to resolve the issue. For Eclipse Jetty versions 9.4.15 and older, update to a version newer than 9.4.15 to resolve the issue. As a temporary workaround, consider restricting access to the DefaultServlet and ResourceHandler to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-04283
CVE-2019-10241
DLA-2661-1
DSA-4949-1
GHSA-7VX9-XJHR-RW6H
OESA-2022-2140
OESA-2022-2148
OESA-2022-2149

Produtos afetados

Astra Linux
Eclipse Jetty