« Volver al listado

CVE-2019-17632

Estado: ModificadaMedia (6.1)—

In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-17632",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "emo@eclipse.org",
      "affectedData": [
        {
          "vendor": "The Eclipse Foundation",
          "product": "Eclipse Jetty",
          "versions": [
            {
              "status": "affected",
              "version": "9.4.21.v20190926"
            },
            {
              "status": "affected",
              "version": "9.4.22.v20191022"
            },
            {
              "status": "affected",
              "version": "9.4.23.v20191118"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-11-25T22:15:11.437",
  "references": [
    {
      "url": "https://bugs.eclipse.org/bugs/show_bug.cgi?id=553443",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SAITZ27GKPD2CCNHGT2VBT4VWIBUJJNS/",
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpuApr2021.html",
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpuoct2020.html",
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://bugs.eclipse.org/bugs/show_bug.cgi?id=553443",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SAITZ27GKPD2CCNHGT2VBT4VWIBUJJNS/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpuApr2021.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpuoct2020.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "emo@eclipse.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output."
    },
    {
      "lang": "es",
      "value": "En Eclipse Jetty versiones 9.4.21.v20190926, 9.4.22.v20191022 y 9.4.23.v20191118, la generación de contenido de respuesta de Error no controlado predeterminado (en Content-Type text/html y text/json ) no escapa a los mensajes Exception en stacktraces incluidos en la salida de error."
    }
  ],
  "lastModified": "2026-06-17T02:24:18.697",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.4.21:20190926:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30BB77C1-F190-40D5-882A-E32B10BD23A3"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.4.22:20191022:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29D0B240-3535-410D-AC4C-F95CEA877CE8"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.4.23:20191118:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "362B1FD4-7862-454F-AB8B-4D2B31601704"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "emo@eclipse.org"
}