6.1

CVE-2019-10241

In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eclipse ≫ Jetty Version 9.2.0 Update 20140523
Eclipse ≫ Jetty Version 9.2.0 Update 20140526
Eclipse ≫ Jetty Version 9.2.0 Update maintenance_0
Eclipse ≫ Jetty Version 9.2.0 Update maintenance_1
Eclipse ≫ Jetty Version 9.2.0 Update rc0
Eclipse ≫ Jetty Version 9.2.1 Update 20140609
Eclipse ≫ Jetty Version 9.2.2 Update 20140723
Eclipse ≫ Jetty Version 9.2.3 Update 20140905
Eclipse ≫ Jetty Version 9.2.4 Update 20141103
Eclipse ≫ Jetty Version 9.2.5 Update 20141112
Eclipse ≫ Jetty Version 9.2.6 Update 20141203
Eclipse ≫ Jetty Version 9.2.6 Update 20141205
Eclipse ≫ Jetty Version 9.2.7 Update 20150116
Eclipse ≫ Jetty Version 9.2.8 Update 20150217
Eclipse ≫ Jetty Version 9.2.9 Update 20150224
Eclipse ≫ Jetty Version 9.2.10 Update 20150310
Eclipse ≫ Jetty Version 9.2.11 Update 20150528
Eclipse ≫ Jetty Version 9.2.11 Update 20150529
Eclipse ≫ Jetty Version 9.2.11 Update maintenance_0
Eclipse ≫ Jetty Version 9.2.12 Update 20150709
Eclipse ≫ Jetty Version 9.2.12 Update maintenance_0
Eclipse ≫ Jetty Version 9.2.13 Update 20150730
Eclipse ≫ Jetty Version 9.2.14 Update 20151106
Eclipse ≫ Jetty Version 9.2.15 Update 20160210
Eclipse ≫ Jetty Version 9.2.16 Update 20160407
Eclipse ≫ Jetty Version 9.2.16 Update 20160414
Eclipse ≫ Jetty Version 9.2.17 Update 20160517
Eclipse ≫ Jetty Version 9.2.18 Update 20160721
Eclipse ≫ Jetty Version 9.2.19 Update 20160908
Eclipse ≫ Jetty Version 9.2.20 Update 20161216
Eclipse ≫ Jetty Version 9.2.21 Update 20170120
Eclipse ≫ Jetty Version 9.2.22 Update 20170606
Eclipse ≫ Jetty Version 9.2.23 Update 20171218
Eclipse ≫ Jetty Version 9.2.24 Update 20180105
Eclipse ≫ Jetty Version 9.2.25 Update 20180606
Eclipse ≫ Jetty Version 9.2.26 Update 20180806
Eclipse ≫ Jetty Version 9.3.0 Update 20150601
Eclipse ≫ Jetty Version 9.3.0 Update 20150608
Eclipse ≫ Jetty Version 9.3.0 Update 20150612
Eclipse ≫ Jetty Version 9.3.0 Update maintenance0
Eclipse ≫ Jetty Version 9.3.0 Update maintenance1
Eclipse ≫ Jetty Version 9.3.0 Update maintenance2
Eclipse ≫ Jetty Version 9.3.0 Update rc0
Eclipse ≫ Jetty Version 9.3.0 Update rc1
Eclipse ≫ Jetty Version 9.3.1 Update 20150714
Eclipse ≫ Jetty Version 9.3.2 Update 20150730
Eclipse ≫ Jetty Version 9.3.3 Update 20150825
Eclipse ≫ Jetty Version 9.3.3 Update 20150827
Eclipse ≫ Jetty Version 9.3.4 Update 20151005
Eclipse ≫ Jetty Version 9.3.4 Update 20151007
Eclipse ≫ Jetty Version 9.3.4 Update rc0
Eclipse ≫ Jetty Version 9.3.4 Update rc1
Eclipse ≫ Jetty Version 9.3.5 Update 20151012
Eclipse ≫ Jetty Version 9.3.6 Update 20151106
Eclipse ≫ Jetty Version 9.3.7 Update 20160115
Eclipse ≫ Jetty Version 9.3.7 Update rc0
Eclipse ≫ Jetty Version 9.3.7 Update rc1
Eclipse ≫ Jetty Version 9.3.8 Update 20160311
Eclipse ≫ Jetty Version 9.3.8 Update 20160314
Eclipse ≫ Jetty Version 9.3.8 Update rc0
Eclipse ≫ Jetty Version 9.3.9 Update 20160517
Eclipse ≫ Jetty Version 9.3.9 Update maintenance_0
Eclipse ≫ Jetty Version 9.3.9 Update maintenance_1
Eclipse ≫ Jetty Version 9.3.10 Update 20160621
Eclipse ≫ Jetty Version 9.3.10 Update maintenance_0
Eclipse ≫ Jetty Version 9.3.11 Update 20160721
Eclipse ≫ Jetty Version 9.3.11 Update maintenance_0
Eclipse ≫ Jetty Version 9.3.12 Update 20160915
Eclipse ≫ Jetty Version 9.3.13 Update 20161014
Eclipse ≫ Jetty Version 9.3.13 Update maintenance_0
Eclipse ≫ Jetty Version 9.3.14 Update 20161028
Eclipse ≫ Jetty Version 9.3.15 Update 20161220
Eclipse ≫ Jetty Version 9.3.16 Update 20170119
Eclipse ≫ Jetty Version 9.3.16 Update 20170120
Eclipse ≫ Jetty Version 9.3.17 Update 20170317
Eclipse ≫ Jetty Version 9.3.17 Update rc0
Eclipse ≫ Jetty Version 9.3.18 Update 20170406
Eclipse ≫ Jetty Version 9.3.19 Update 20170502
Eclipse ≫ Jetty Version 9.3.20 Update 20170531
Eclipse ≫ Jetty Version 9.3.21 Update 20170918
Eclipse ≫ Jetty Version 9.3.21 Update maintenance_0
Eclipse ≫ Jetty Version 9.3.21 Update rc0
Eclipse ≫ Jetty Version 9.3.22 Update 20171030
Eclipse ≫ Jetty Version 9.3.23 Update 20180228
Eclipse ≫ Jetty Version 9.3.24 Update 20180605
Eclipse ≫ Jetty Version 9.3.25 Update 20180904
Eclipse ≫ Jetty Version 9.4.0 Update 20161207
Eclipse ≫ Jetty Version 9.4.0 Update 20161208
Eclipse ≫ Jetty Version 9.4.0 Update 20180619
Eclipse ≫ Jetty Version 9.4.0 Update maintenance_0
Eclipse ≫ Jetty Version 9.4.0 Update maintenance_1
Eclipse ≫ Jetty Version 9.4.0 Update rc0
Eclipse ≫ Jetty Version 9.4.0 Update rc1
Eclipse ≫ Jetty Version 9.4.0 Update rc2
Eclipse ≫ Jetty Version 9.4.0 Update rc3
Eclipse ≫ Jetty Version 9.4.1 Update 20170120
Eclipse ≫ Jetty Version 9.4.1 Update 20180619
Eclipse ≫ Jetty Version 9.4.2 Update 20170220
Eclipse ≫ Jetty Version 9.4.2 Update 20180619
Eclipse ≫ Jetty Version 9.4.3 Update 20170317
Eclipse ≫ Jetty Version 9.4.3 Update 20180619
Eclipse ≫ Jetty Version 9.4.4 Update 20170410
Eclipse ≫ Jetty Version 9.4.4 Update 20170414
Eclipse ≫ Jetty Version 9.4.4 Update 20180619
Eclipse ≫ Jetty Version 9.4.5 Update 20170502
Eclipse ≫ Jetty Version 9.4.5 Update 20180619
Eclipse ≫ Jetty Version 9.4.6 Update 20170531
Eclipse ≫ Jetty Version 9.4.6 Update 20180619
Eclipse ≫ Jetty Version 9.4.7 Update 20170914
Eclipse ≫ Jetty Version 9.4.7 Update 20180619
Eclipse ≫ Jetty Version 9.4.7 Update rc0
Eclipse ≫ Jetty Version 9.4.8 Update 20171121
Eclipse ≫ Jetty Version 9.4.8 Update 20180619
Eclipse ≫ Jetty Version 9.4.9 Update 20180320
Eclipse ≫ Jetty Version 9.4.10 Update 20180503
Eclipse ≫ Jetty Version 9.4.10 Update rc0
Eclipse ≫ Jetty Version 9.4.10 Update rc1
Eclipse ≫ Jetty Version 9.4.11 Update 20180605
Eclipse ≫ Jetty Version 9.4.12 Update 20180830
Eclipse ≫ Jetty Version 9.4.12 Update rc0
Eclipse ≫ Jetty Version 9.4.12 Update rc1
Eclipse ≫ Jetty Version 9.4.12 Update rc2
Eclipse ≫ Jetty Version 9.4.13 Update 20181111
Eclipse ≫ Jetty Version 9.4.14 Update 20181114
Eclipse ≫ Jetty Version 9.4.15 Update 20190215
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Apache ≫ Activemq Version 5.15.9
Apache ≫ Drill Version 1.16.0
Oracle ≫ Flexcube Core Banking Version >= 11.5.0 <= 11.7.0
Oracle ≫ Flexcube Core Banking Version 5.2.0
Oracle ≫ Rest Data Services Version 11.2.0.4 SwEdition -
Oracle ≫ Rest Data Services Version 12.1.0.2 SwEdition -
Oracle ≫ Rest Data Services Version 12.2.0.1 SwEdition -
Oracle ≫ Rest Data Services Version 18c SwEdition -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.59% 0.949
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
https://www.oracle.com/security-alerts/cpuoct2020.html
Patch
Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Patch
Third Party Advisory
https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/ac51944aef91dd5006b8510b0bef337adaccfe962fb90e7af9c22db4%40%3Cissues.activemq.apache.org%3E
https://lists.debian.org/debian-lts-announce/2021/05/msg00016.html
Third Party Advisory
Mailing List
https://bugs.eclipse.org/bugs/show_bug.cgi?id=546121
Vendor Advisory
Issue Tracking
https://lists.apache.org/thread.html/01e004c3f7c7365863a27e7038b7f32dae56ccf3a496b277c9b7f7b6%40%3Cjira.kafka.apache.org%3E
https://lists.apache.org/thread.html/464892b514c029dfc0c8656a93e1c0de983c473df70fdadbd224e09f%40%3Cjira.kafka.apache.org%3E
https://lists.apache.org/thread.html/8bff534863c7aaf09bb17c3d0532777258dd3a5c7ddda34198cc2742%40%3Cdev.kafka.apache.org%3E
https://lists.apache.org/thread.html/bcfb37bfba7b3d7e9c7808b5e5a38a98d6bb714d52cf5162bdd48e32%40%3Cjira.kafka.apache.org%3E
https://lists.apache.org/thread.html/d7c4a664a34853f57c2163ab562f39802df5cf809523ea40c97289c1%40%3Cdev.kafka.apache.org%3E
https://security.netapp.com/advisory/ntap-20190509-0003/
Third Party Advisory
https://www.debian.org/security/2021/dsa-4949
Third Party Advisory