CVEs (52)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian EclipseNetapp+1 more26Autovue Communications AnalyticsCommunications Element Manager+23 moreJun 17, 2026 Apr 22, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource l...Show more |
3Eclipse NetappOracle25Autovue Communications AnalyticsCommunications Element Manager+22 moreJun 17, 2026 Apr 22, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for sho...Show more |
4Apache DebianEclipse+1 more7Activemq Debian LinuxDrill+4 moreJun 17, 2026 Apr 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandle...Show more |
2Eclipse Fedoraproject2Fedora JettyNov 21, 2024 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames....Show more |
2Eclipse Oracle2Jetty Retail Xstore Point Of ServiceNov 21, 2024 Jun 27, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServl...Show more |
5Debian EclipseHp+2 more19Debian Linux E Series Santricity ManagementE Series Santricity Os Controller+16 moreNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When present...Show more |
5Debian EclipseHp+2 more17Debian Linux E Series Santricity ManagementE Series Santricity Os Controller+14 moreNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vul...Show more |
2Debian Eclipse2Debian Linux JettyNov 21, 2024 Jun 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space U...Show more |
2Eclipse Netapp12E Series Santricity Management Plug Ins E Series Santricity Os ControllerE Series Santricity Web Services Proxy+9 moreNov 21, 2024 Jun 22, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSes...Show more |
3Debian EclipseOracle7Communications Cloud Native Core Policy Debian LinuxEnterprise Manager Base Platform+4 moreMay 13, 2026 Jun 16, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords. |
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certai...Show more |
2Eclipse Fedoraproject2Fedora JettyMay 6, 2026 Oct 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak. |