SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-10241

In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing…

MEDIUM 6.1EPSS 9.63%

Does this matter?

Lower severity and a low EPSS score (9.63%). Track it; it rarely justifies an emergency change on its own.

Description

In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
9.63% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
eclipse/jetty · debian/debian linux · apache/activemq · apache/drill · oracle/flexcube core banking · oracle/rest data services · oracle/retail xstore point of service
Source
emo@eclipse.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.