CVE-2019-10247

MEDIUMCVSS 5.3/10EPSS 5.78%

Last modified

CVE-2019-10247 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on jetty-distribution and jetty-home will include at the end of the Handler tree a DefaultHandler, which is responsible for reporting this 404 error, it presents the various configured contexts as HTML for users to click through to. EPSS estimates a 5.78% chance of exploitation in the next 30 days.

Description

In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on jetty-distribution and jetty-home will include at the end of the Handler tree a DefaultHandler, which is responsible for reporting this 404 error, it presents the various configured contexts as HTML for users to click through to. This produced HTML includes output that contains the configured fully qualified directory base resource location for each context.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS Probability
5.78%

92.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
EclipseJetty7.0.020091005
EclipseJetty7.0.120091125
EclipseJetty7.0.220100331
EclipseJetty7.1.020100505
EclipseJetty7.1.120100517
EclipseJetty7.1.220100523
EclipseJetty7.1.320100526
EclipseJetty7.1.420100610
EclipseJetty7.1.520100705
EclipseJetty7.1.620100715
EclipseJetty7.2.020101020
EclipseJetty7.2.120101111
EclipseJetty7.2.220101205
EclipseJetty7.3.020110203
EclipseJetty7.3.120110307
EclipseJetty7.4.020110414
EclipseJetty7.4.120110513
EclipseJetty7.4.220110526
EclipseJetty7.4.320110630
EclipseJetty7.4.420110707
EclipseJetty7.4.520110725
EclipseJetty7.5.020110901
EclipseJetty7.5.120110908
EclipseJetty7.5.220111006
EclipseJetty7.5.320111011
EclipseJetty7.5.420111024
EclipseJetty7.6.020120125
EclipseJetty7.6.120120215
EclipseJetty7.6.220120302
EclipseJetty7.6.320120413
EclipseJetty7.6.420120522
EclipseJetty7.6.520120713
EclipseJetty7.6.620120903
EclipseJetty7.6.720120910
EclipseJetty7.6.820121106
EclipseJetty7.6.920130131
EclipseJetty7.6.1020130312
EclipseJetty7.6.1120130520
EclipseJetty7.6.1220130726
EclipseJetty7.6.1320130910
EclipseJetty7.6.1420131031
EclipseJetty7.6.1520140411
EclipseJetty7.6.1620140903
EclipseJetty7.6.1720150415
EclipseJetty7.6.1820150929
EclipseJetty7.6.1920160209
EclipseJetty7.6.2020160902
EclipseJetty7.6.2120160908
EclipseJetty8.0.020110901
EclipseJetty8.0.120110908

Showing 50 of 210 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-10247?
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on jetty-distribution and jetty-home will include at the end of the Handler tree a DefaultHandler, which is responsible for reporting this 404 error, it presents the various configured contexts as HTML for users to click through to. This produced HTML includes output that contains the configured fully qualified directory base resource location for each context.
How severe is CVE-2019-10247?
CVE-2019-10247 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 5.78% probability of exploitation in the next 30 days.
How do I fix CVE-2019-10247?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-10247?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST