Search CVE reports
31 – 40 of 45 results
CVE-2017-7656
Medium priorityIn Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space...
2 affected packages
jetty8, jetty9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jetty8 | Not in release | Not in release | Not in release | Not in release | Ignored |
jetty9 | Not affected | Not affected | Not affected | Vulnerable | Vulnerable |
CVE-2018-12538
Medium priorityIn Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and...
2 affected packages
jetty, jetty9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jetty | — | — | — | Not in release | Not affected |
jetty9 | — | — | — | Not affected | Not affected |
CVE-2017-9735
Medium prioritySome fixes available 2 of 9
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
3 affected packages
jetty, jetty8, jetty9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jetty | Not in release | Not in release | Not in release | Not in release | Fixed |
jetty8 | Not in release | Not in release | Not in release | Not in release | Vulnerable |
jetty9 | Not affected | Not affected | Not affected | Not affected | Vulnerable |
CVE-2016-4800
Medium priorityThe path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped...
3 affected packages
jetty, jetty8, jetty9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jetty | — | — | — | — | Not affected |
jetty8 | — | — | — | — | Not affected |
jetty9 | — | — | — | — | Not affected |
CVE-2015-2080
Medium priorityThe exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.
2 affected packages
jetty, jetty8
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jetty | — | — | — | — | — |
jetty8 | — | — | — | — | — |
CVE-2011-4461
Medium prioritySome fixes available 3 of 8
Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending...
1 affected packages
jetty
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jetty | — | — | — | — | — |
CVE-2011-4404
Medium priorityThe default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read...
1 affected packages
jetty
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jetty | — | — | — | — | — |
CVE-2009-4612
Low priorityMultiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1)...
1 affected packages
jetty
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jetty | — | — | — | — | — |
CVE-2009-4611
Negligible priorityMort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace data without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite...
1 affected packages
jetty
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jetty | — | — | — | — | — |
CVE-2009-4610
Low priorityMultiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to jsp/dump.jsp in the JSP Dump feature, or the (2) Name or...
1 affected packages
jetty
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jetty | — | — | — | — | — |