← back
CVE-2019-10241

CVE-2019-10241

EPSS 9.6%CWE-79
In short

Eclipse Jetty servers can be tricked into showing malicious code in the browser when displaying directory listings if someone visits a specially crafted URL. This allows attackers to steal user information or perform actions on their behalf.

Technical detail

A reflected XSS vulnerability exists in DefaultServlet and ResourceHandler when directory listing is enabled. The attack vector involves a specially formatted URL that bypasses input sanitization in the directory listing output, allowing arbitrary JavaScript execution in the victim's browser context.

Summary generated and translated by AI from the official description.
In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →