CVEs (51)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org...Show more |
3Debian EclipseNetapp6Active Iq Unified Manager Debian LinuxE Series Santricity Os Controller+3 moreJun 17, 2026 Apr 18, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookies, or otherwise perform unintended behavior by tampering with the cooki...Show more |
Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotated with `@MultipartConfig`) that call `HttpServletRequest.getParameter()` or `HttpServletRequest.getP...Show more |
In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths. |
4Debian EclipseJenkins+1 more8Debian Linux Element Plug In For Vcenter ServerHci Compute Node+5 moreJun 17, 2026 Jul 7, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can...Show more |
3Debian EclipseNetapp7Debian Linux Element Plug In For Vcenter ServerHci Compute Node+4 moreJun 17, 2026 Jul 7, 2022 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid inpu...Show more |
3Eclipse NetappOracle18Autovue For Agile Product Lifecycle Management Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Security Edge Protection Proxy+15 moreJun 17, 2026 Jul 15, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a...Show more |
4Debian EclipseNetapp+1 more16Active Iq Unified Manager Autovue For Agile Product Lifecycle ManagementCommunications Element Manager+13 moreJun 17, 2026 Jun 22, 2021 N/A· v4 3.5 LOW· v3 3.6 LOW· v2 For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments w...Show more |
4Debian EclipseNetapp+1 more8Active Iq Unified Manager Communications Cloud Native Core PolicyDebian Linux+5 moreJun 17, 2026 Jun 9, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to...Show more |
4Eclipse JenkinsNetapp+1 more21Autovue For Agile Product Lifecycle Management Cloud ManagerCommunications Cloud Native Core Policy+18 moreJun 17, 2026 Apr 1, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. |
3Eclipse NetappOracle17Autovue For Agile Product Lifecycle Management Banking ApisBanking Digital Experience+14 moreJun 17, 2026 Apr 1, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a r...Show more |
5Apache EclipseFedoraproject+2 more23Autovue For Agile Product Lifecycle Management Banking ApisBanking Digital Experience+20 moreJun 17, 2026 Apr 1, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadverte...Show more |
5Apache DebianEclipse+2 more16Debian Linux E Series Santricity Os ControllerE Series Santricity Web Services+13 moreJun 17, 2026 Feb 26, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may en...Show more |
5Apache DebianEclipse+2 more17Blockchain Platform Communications Converged Application Server Service ControllerCommunications Offline Mediation Controller+14 moreJun 17, 2026 Nov 28, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto...Show more |
5Apache DebianEclipse+2 more18Beam Communications Application Session ControllerCommunications Converged Application Server Service Controller+15 moreJun 17, 2026 Oct 23, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that syste...Show more |
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP respon...Show more |
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages...Show more |
2Debian Eclipse2Debian Linux JettyNov 21, 2024 Nov 6, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22. |
2Debian Eclipse2Debian Linux JettyNov 21, 2024 Nov 6, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dump Servlet information leak in jetty before 6.1.22. |
4Debian EclipseNetapp+1 more26Autovue Communications AnalyticsCommunications Element Manager+23 moreJun 17, 2026 Apr 22, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource l...Show more |