Reflected cross-site scripting (XSS) In org.eclipse.jetty:jetty-server
Description
Unescaped exception messages in error responses in Jetty In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 9.4.24.v20191120, 9.4.24.v20191120, 9.4.24.v20191120 | ||
debian 14 | 9.4.26-1 | ||
debian 11 | 9.4.26-1 | ||
maven | 9.4.24.v20191120 | ||
debian 12 | 9.4.26-1 | ||
debian 13 | 9.4.26-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4.