CVE-2019-10241

MEDIUM

Eclipse Jetty <= 9.2.26, <= 9.3.25, <= 9.4.15 - Cross-Site Scripting via Directory Listing

Title source: llm
STIX 2.1

Description

In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.

References (15)

Core 15
Core References
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190509-0003/
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2020.html
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugs.eclipse.org/bugs/show_bug.cgi?id=546121
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2021/05/msg00016.html
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-4949

Scores

CVSS v3 6.1
EPSS 0.0969
EPSS Percentile 93.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (34)
apache/activemq 5.15.9
apache/drill 1.16.0
debian/debian_linux 9.0
debian/debian_linux 10.0
eclipse/jetty 9.2.0 20140523 (5 CPE variants)
eclipse/jetty 9.2.1 20140609
eclipse/jetty 9.2.2 20140723
eclipse/jetty 9.2.3 20140905
eclipse/jetty 9.2.4 20141103
eclipse/jetty 9.2.5 20141112
... and 24 more
Published Apr 22, 2019
Tracked Since Feb 18, 2026