In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation...
Vulnerability Description
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-17632
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- This vulnerability was discovered by Jon Are Rakvåg, Security architect, SpareBank 1 Utvikling and Erlend Leiknes, Security Consultant, mnemonic as
References
More from The Eclipse Foundation
View All →Affected Vendor
The Eclipse Foundation
View all reports →