PT-2019-3890 · Eclipse+1 · Eclipse Jetty+1
Publicado
2019-04-04
·
Atualizado
2022-12-24
·
CVE-2019-10241
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Eclipse Jetty versions 9.2.26 and older
Eclipse Jetty versions 9.3.25 and older
Eclipse Jetty versions 9.4.15 and older
Description
The server is vulnerable to XSS conditions if a remote client uses a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a listing of directory contents. This issue arises due to the lack of protection for the web page structure, allowing a remote attacker to conduct XSS attacks by using a specially formatted URL.
Recommendations
For Eclipse Jetty versions 9.2.26 and older, update to a version newer than 9.2.26 to resolve the issue.
For Eclipse Jetty versions 9.3.25 and older, update to a version newer than 9.3.25 to resolve the issue.
For Eclipse Jetty versions 9.4.15 and older, update to a version newer than 9.4.15 to resolve the issue.
As a temporary workaround, consider restricting access to the DefaultServlet and ResourceHandler to minimize the risk of exploitation.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Astra Linux
Eclipse Jetty