CVE-2019-10246
published 2019-04-22CVE-2019-10246: In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
4.02%
89.4th percentile
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jetty9 | — | — |
| eclipse | jetty | — | — |
| eclipse | jetty | — | — |
| eclipse | jetty | — | — |
| netapp | oncommand_system_manager | 3.0 – 3.1.3 | — |
| netapp | storage_replication_adapter_for_clustered_data_ontap | — | — |
| netapp | storage_replication_adapter_for_clustered_data_ontap | >= 9.6 | — |
| netapp | vasa_provider_for_clustered_data_ontap | >= 9.6 | — |
| netapp | virtual_storage_console | — | — |
| netapp | virtual_storage_console | >= 9.6 | — |
| oracle | autovue | — | — |
| oracle | communications_analytics | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_services_gatekeeper | — | — |
| oracle | communications_services_gatekeeper | — | — |
| oracle | communications_services_gatekeeper | — | — |
| oracle | communications_session_report_manager | — | — |
| oracle | communications_session_report_manager | — | — |
| oracle | communications_session_report_manager | — | — |
| oracle | communications_session_report_manager | — | — |
| oracle | communications_session_route_manager | — | — |
| oracle | communications_session_route_manager | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jetty: Directory Listing on Windows reveals Resource Base path
vendor_redhat·2019-04-15·CVSS 5.3
CVE-2019-10246 [MEDIUM] CWE-200 jetty: Directory Listing on Windows reveals Resource Base path
jetty: Directory Listing on Windows reveals Resource Base path
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.
A flaw was found in Eclipse Jetty. This issue may lead to exposure of the fully qualified Base Resource directory name on Windows to a remote client when configured to show a listing of directory contents. By sending a specially-crafted request, a remote attacker could obtain sensitive information.
Statement: This CVE only impacts users using Eclipse Jetty on Windows.
P
Debian
CVE-2019-10246: jetty9 - In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windo...
vendor_debian·2019·CVSS 5.3
CVE-2019-10246 [MEDIUM] CVE-2019-10246: jetty9 - In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windo...
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
Information Exposure vulnerability in Eclipse Jetty
ghsa·2019-04-23
CVE-2019-10246 [MEDIUM] CWE-200 Information Exposure vulnerability in Eclipse Jetty
Information Exposure vulnerability in Eclipse Jetty
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.
OSV
Information Exposure vulnerability in Eclipse Jetty
osv·2019-04-23
CVE-2019-10246 [MEDIUM] Information Exposure vulnerability in Eclipse Jetty
Information Exposure vulnerability in Eclipse Jetty
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.eclipse.org/bugs/show_bug.cgi?id=546576https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3Ehttps://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190509-0003/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://bugs.eclipse.org/bugs/show_bug.cgi?id=546576https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3Ehttps://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190509-0003/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2019-04-22
Published