PT-2019-3890 · Eclipse+1 · Eclipse Jetty+1

Published

2019-04-04

·

Updated

2022-12-24

·

CVE-2019-10241

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Jetty versions 9.2.26 and older Eclipse Jetty versions 9.3.25 and older Eclipse Jetty versions 9.4.15 and older
Description The server is vulnerable to XSS conditions if a remote client uses a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a listing of directory contents. This issue arises due to the lack of protection for the web page structure, allowing a remote attacker to conduct XSS attacks by using a specially formatted URL.
Recommendations For Eclipse Jetty versions 9.2.26 and older, update to a version newer than 9.2.26 to resolve the issue. For Eclipse Jetty versions 9.3.25 and older, update to a version newer than 9.3.25 to resolve the issue. For Eclipse Jetty versions 9.4.15 and older, update to a version newer than 9.4.15 to resolve the issue. As a temporary workaround, consider restricting access to the DefaultServlet and ResourceHandler to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04283
CVE-2019-10241
DLA-2661-1
DSA-4949-1
GHSA-7VX9-XJHR-RW6H
OESA-2022-2140
OESA-2022-2148
OESA-2022-2149

Affected Products

Astra Linux
Eclipse Jetty