CVE-2019-10241
Last modified
CVE-2019-10241 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.. EPSS estimates a 9.59% chance of exploitation in the next 30 days.
Description
In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Eclipse | Jetty | 9.2.0 | 20140523 |
| Eclipse | Jetty | 9.2.1 | 20140609 |
| Eclipse | Jetty | 9.2.2 | 20140723 |
| Eclipse | Jetty | 9.2.3 | 20140905 |
| Eclipse | Jetty | 9.2.4 | 20141103 |
| Eclipse | Jetty | 9.2.5 | 20141112 |
| Eclipse | Jetty | 9.2.6 | 20141203 |
| Eclipse | Jetty | 9.2.7 | 20150116 |
| Eclipse | Jetty | 9.2.8 | 20150217 |
| Eclipse | Jetty | 9.2.9 | 20150224 |
| Eclipse | Jetty | 9.2.10 | 20150310 |
| Eclipse | Jetty | 9.2.11 | 20150528 |
| Eclipse | Jetty | 9.2.12 | 20150709 |
| Eclipse | Jetty | 9.2.13 | 20150730 |
| Eclipse | Jetty | 9.2.14 | 20151106 |
| Eclipse | Jetty | 9.2.15 | 20160210 |
| Eclipse | Jetty | 9.2.16 | 20160407 |
| Eclipse | Jetty | 9.2.17 | 20160517 |
| Eclipse | Jetty | 9.2.18 | 20160721 |
| Eclipse | Jetty | 9.2.19 | 20160908 |
| Eclipse | Jetty | 9.2.20 | 20161216 |
| Eclipse | Jetty | 9.2.21 | 20170120 |
| Eclipse | Jetty | 9.2.22 | 20170606 |
| Eclipse | Jetty | 9.2.23 | 20171218 |
| Eclipse | Jetty | 9.2.24 | 20180105 |
| Eclipse | Jetty | 9.2.25 | 20180606 |
| Eclipse | Jetty | 9.2.26 | 20180806 |
| Eclipse | Jetty | 9.3.0 | 20150601 |
| Eclipse | Jetty | 9.3.1 | 20150714 |
| Eclipse | Jetty | 9.3.2 | 20150730 |
| Eclipse | Jetty | 9.3.3 | 20150825 |
| Eclipse | Jetty | 9.3.4 | 20151005 |
| Eclipse | Jetty | 9.3.5 | 20151012 |
| Eclipse | Jetty | 9.3.6 | 20151106 |
| Eclipse | Jetty | 9.3.7 | 20160115 |
| Eclipse | Jetty | 9.3.8 | 20160311 |
| Eclipse | Jetty | 9.3.9 | 20160517 |
| Eclipse | Jetty | 9.3.10 | 20160621 |
| Eclipse | Jetty | 9.3.11 | 20160721 |
| Eclipse | Jetty | 9.3.12 | 20160915 |
| Eclipse | Jetty | 9.3.13 | 20161014 |
| Eclipse | Jetty | 9.3.14 | 20161028 |
| Eclipse | Jetty | 9.3.15 | 20161220 |
| Eclipse | Jetty | 9.3.16 | 20170119 |
| Eclipse | Jetty | 9.3.17 | 20170317 |
| Eclipse | Jetty | 9.3.18 | 20170406 |
| Eclipse | Jetty | 9.3.19 | 20170502 |
| Eclipse | Jetty | 9.3.20 | 20170531 |
| Eclipse | Jetty | 9.3.21 | 20170918 |
| Eclipse | Jetty | 9.3.22 | 20171030 |
Showing 50 of 83 affected configurations. See NVD for the full list.
References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=546121Issue Tracking, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/05/msg00016.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190509-0003/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4949Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlPatch, Third Party Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=546121Issue Tracking, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/05/msg00016.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190509-0003/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4949Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-10241?
How severe is CVE-2019-10241?
How do I fix CVE-2019-10241?
Are you affected by CVE-2019-10241?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
