This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Mortbay First view 2005-11-22
Product Jetty Last view 2019-11-06
Version 3.1.6 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:mortbay:jetty

Activity : Overall

Related : CVE

  Date Alert Description
6.1 2019-11-06 CVE-2009-5049

WebApp JSP Snoop page XSS in jetty though 6.1.21.

6.1 2019-11-06 CVE-2009-5048

Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.

5.3 2011-12-29 CVE-2011-4461

Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

4.3 2009-05-05 CVE-2009-1524

Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) character.

5 2009-05-05 CVE-2009-1523

Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.

5 2005-11-22 CVE-2005-3747

Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758.

CWE : Common Weakness Enumeration

%idName
50% (3) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
16% (1) CWE-310 Cryptographic Issues
16% (1) CWE-200 Information Exposure
16% (1) CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path ...

Open Source Vulnerability Database (OSVDB)

id Description
78117 Jetty Hash Collission Form Parameter Parsing Remote DoS
54187 Jetty Directory Listing Semicolon Character XSS
54186 Jetty HTTP Server Document Root Traversal Arbitrary File Access
21000 Jetty Unspecified JSP Source Code Disclosure

OpenVAS Exploits

id Description
2012-04-30 Name : Ubuntu Update for jetty USN-1429-1
File : nvt/gb_ubuntu_USN_1429_1.nasl
2012-03-26 Name : Fedora Update for jetty FEDORA-2012-0730
File : nvt/gb_fedora_2012_0730_jetty_fc16.nasl
2012-03-26 Name : Fedora Update for jetty FEDORA-2012-0752
File : nvt/gb_fedora_2012_0752_jetty_fc15.nasl
2009-11-11 Name : Mandriva Security Advisory MDVSA-2009:291 (jetty5)
File : nvt/mdksa_2009_291.nasl
2009-06-05 Name : Fedora Core 9 FEDORA-2009-5500 (jetty)
File : nvt/fcore_2009_5500.nasl
2009-06-05 Name : Fedora Core 11 FEDORA-2009-5509 (jetty)
File : nvt/fcore_2009_5509.nasl
2009-06-05 Name : Fedora Core 10 FEDORA-2009-5513 (jetty)
File : nvt/fcore_2009_5513.nasl
2009-05-04 Name : Jetty Cross Site Scripting and Information Disclosure Vulnerabilities
File : nvt/jetty_34800.nasl

Nessus® Vulnerability Scanner

id Description
2015-01-26 Name: The remote host has an enterprise management application installed that is af...
File: oracle_enterprise_manager_jan_2015_cpu.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2012-128.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_4_jetty5-120215.nasl - Type: ACT_GATHER_INFO
2012-04-27 Name: The remote Ubuntu host is missing a security-related patch.
File: ubuntu_USN-1429-1.nasl - Type: ACT_GATHER_INFO
2012-03-26 Name: The remote Fedora host is missing a security update.
File: fedora_2012-0730.nasl - Type: ACT_GATHER_INFO
2012-03-26 Name: The remote Fedora host is missing a security update.
File: fedora_2012-0752.nasl - Type: ACT_GATHER_INFO
2011-08-24 Name: The remote web server has a cross-site scripting vulnerability.
File: hadoop_jetty_xss.nasl - Type: ACT_GATHER_INFO
2011-02-17 Name: The remote host has an update manager installed that is affected by multiple ...
File: vmware_VMSA-2010-0012.nasl - Type: ACT_GATHER_INFO
2010-07-29 Name: The remote web server has a cross-site scripting vulnerability.
File: vmware_vcenter_update_mgr_xss.nasl - Type: ACT_GATHER_INFO
2009-11-11 Name: The remote openSUSE host is missing a security update.
File: suse_11_2_jetty5-091109.nasl - Type: ACT_GATHER_INFO
2009-10-30 Name: The remote Mandriva Linux host is missing one or more security updates.
File: mandriva_MDVSA-2009-291.nasl - Type: ACT_GATHER_INFO
2009-05-27 Name: The remote Fedora host is missing a security update.
File: fedora_2009-5500.nasl - Type: ACT_GATHER_INFO
2009-05-27 Name: The remote Fedora host is missing a security update.
File: fedora_2009-5509.nasl - Type: ACT_GATHER_INFO
2009-05-27 Name: The remote Fedora host is missing a security update.
File: fedora_2009-5513.nasl - Type: ACT_GATHER_INFO
2006-11-22 Name: The remote HP-UX host is missing a security-related patch.
File: hpux_PHSS_35436.nasl - Type: ACT_GATHER_INFO
2006-11-22 Name: The remote HP-UX host is missing a security-related patch.
File: hpux_PHSS_35437.nasl - Type: ACT_GATHER_INFO