QID 982260

QID 982260: Java (maven) Security Update for org.eclipse.jetty:jetty-server (GHSA-r28m-g6j9-r2h5)

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-r28m-g6j9-r2h5 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982260

    Software Advisories
    Advisory ID Software Component Link
    GHSA-r28m-g6j9-r2h5 org.eclipse.jetty:jetty-server URL Logo github.com/advisories/GHSA-r28m-g6j9-r2h5