QID 982254
QID 982254: Java (maven) Security Update for org.eclipse.jetty:jetty-server (GHSA-5h9j-q6j2-253f)
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5h9j-q6j2-253f for updates pertaining to this vulnerability.
Vendor References
- GHSA-5h9j-q6j2-253f -
github.com/advisories/GHSA-5h9j-q6j2-253f
CVEs related to QID 982254
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5h9j-q6j2-253f | org.eclipse.jetty:jetty-server |
|