Jetty Dump Servlet Cross Site Scripting Vulnerability
BID:26697
Info
Jetty Dump Servlet Cross Site Scripting Vulnerability
| Bugtraq ID: | 26697 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5613 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2007 12:00AM |
| Updated: | Apr 16 2015 06:11PM |
| Credit: | Tomasz Kuczynski is credited with the discovery of this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 10 SP2 Jetty Jetty 6.0.2 Jetty Jetty 6.0.1 Jetty Jetty 6.1.5 Jetty Jetty 6.1.4 Jetty Jetty 6.1.3 Jetty Jetty 6.1.2 Jetty Jetty 6.1.1 Jetty Jetty 6.1.0pre3 Jetty Jetty 6.1.0pre2 |
| Not Vulnerable: |
Jetty Jetty 6.1.6 |
Discussion
Jetty Dump Servlet Cross Site Scripting Vulnerability
Jetty is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue allows an attacker to execute arbitrary HTML or script code in a user's browser session in the context of an affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to Jetty 6.1.6 are vulnerable.
Jetty is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue allows an attacker to execute arbitrary HTML or script code in a user's browser session in the context of an affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to Jetty 6.1.6 are vulnerable.
Exploit / POC
Jetty Dump Servlet Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Jetty Dump Servlet Cross Site Scripting Vulnerability
Solution:
The vendor released Jetty 6.1.6 to address this issue. Please see the references for more information.
Jetty Jetty 6.1.0pre2
Jetty Jetty 6.1.4
Jetty Jetty 6.1.3
Jetty Jetty 6.1.1
Jetty Jetty 6.1.5
Jetty Jetty 6.1.2
Jetty Jetty 6.1.0pre3
Jetty Jetty 6.0.1
Jetty Jetty 6.0.2
Solution:
The vendor released Jetty 6.1.6 to address this issue. Please see the references for more information.
Jetty Jetty 6.1.0pre2
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.1.4
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.1.3
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.1.1
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.1.5
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.1.2
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.1.0pre3
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.0.1
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.0.2
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
References
Jetty Dump Servlet Cross Site Scripting Vulnerability
References:
References:
- Jetty Changelog (Jetty)
- Jetty Homepage (Jetty)
- Vulnerability Note VU#237888 (US-CERT)
- Dump Servlet - prevent possible cross site scripting - CERT VU#237888 (David Yu)