QID 150349
Date Published: 2021-04-27
QID 150349: Jetty Server 9.4.21-23 XSS Vulnerability
Eclipse Jetty software is a web server.
Eclipse Jetty versions 9.4.21-23 does not escape the user input in the default unhandled error response containing call stack leads to XSS vulnerability.
Detection Logic:
This vulnerability is detected based on Jetty version detected.
XSS exploits pose a significant threat to a Web application, its users and user data. XSS exploits target the users of a Web application rather than the Web application itself. An exploit can lead to theft of the user's credentials and personal or financial information. Complex exploits and attack scenarios are possible via XSS because it enables an attacker to execute dynamic code. Consequently, any capability or feature available to the Web browser (for example HTML, JavaScript, Flash and Java applets) can be used to as a part of a compromise.
Versions Impacted:
- 9.4.21.v20190926
- 9.4.22.v20191022
- 9.4.23.v20191118
Upgrade to 9.4.24.v20191120 or turn off Stacktraces in the Generic ErrorHandler.
for more details refer to https://bugs.eclipse.org/bugs/show_bug.cgi?id=553443
CVEs related to QID 150349
| Advisory ID | Software | Component | Link |
|---|