QID 982260
QID 982260: Java (maven) Security Update for org.eclipse.jetty:jetty-server (GHSA-r28m-g6j9-r2h5)
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-r28m-g6j9-r2h5 for updates pertaining to this vulnerability.
Vendor References
- GHSA-r28m-g6j9-r2h5 -
github.com/advisories/GHSA-r28m-g6j9-r2h5
CVEs related to QID 982260
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r28m-g6j9-r2h5 | org.eclipse.jetty:jetty-server |
|