CVE-2019-17632
published 2019-11-25CVE-2019-17632: In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.91%
77.4th percentile
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jetty9 | < jetty9 9.4.26-1 (bookworm) | jetty9 9.4.26-1 (bookworm) |
| eclipse | jetty | — | — |
| eclipse | jetty | — | — |
| eclipse | jetty | — | — |
| the_eclipse_foundation | eclipse_jetty | — | — |
| the_eclipse_foundation | eclipse_jetty | — | — |
| the_eclipse_foundation | eclipse_jetty | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jetty: generation of default unhandled error response content does not escape exception messages in stacktraces included in error output
vendor_redhat·2019-11-25·CVSS 6.1
CVE-2019-17632 [MEDIUM] CWE-79 jetty: generation of default unhandled error response content does not escape exception messages in stacktraces included in error output
jetty: generation of default unhandled error response content does not escape exception messages in stacktraces included in error output
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.
Package: jetty-eclipse (Red Hat Enterprise Linux 6) - Not affected
Package: jetty (Red Hat Enterprise Linux 7) - Not affected
Package: jetty (Red Hat Fuse 7) - Not affected
Package: jetty (Red Hat JBoss Fuse 6) - Out of support scope
Package: jetty (Red Hat JBoss Fuse Service Works 6) - Out of support scope
Package: nutch (Red Hat Satellite 5) - Out of support scope
Package: jetty (Red Hat S
Debian
CVE-2019-17632: jetty9 - In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v201911...
vendor_debian·2019·CVSS 6.1
CVE-2019-17632 [MEDIUM] CVE-2019-17632: jetty9 - In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v201911...
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.
Scope: local
bookworm: resolved (fixed in 9.4.26-1)
bullseye: resolved (fixed in 9.4.26-1)
forky: resolved (fixed in 9.4.26-1)
sid: resolved (fixed in 9.4.26-1)
trixie: resolved (fixed in 9.4.26-1)
GHSA
Unescaped exception messages in error responses in Jetty
ghsa·2019-12-02
CVE-2019-17632 [MEDIUM] CWE-79 Unescaped exception messages in error responses in Jetty
Unescaped exception messages in error responses in Jetty
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.
OSV
Unescaped exception messages in error responses in Jetty
osv·2019-12-02
CVE-2019-17632 [MEDIUM] Unescaped exception messages in error responses in Jetty
Unescaped exception messages in error responses in Jetty
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.
OSV
CVE-2019-17632: In Eclipse Jetty versions 9
osv·2019-11-25·CVSS 6.1
CVE-2019-17632 [MEDIUM] CVE-2019-17632: In Eclipse Jetty versions 9
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-17632 jetty: generation of default unhandled error response content does not escape exception messages in stacktraces included in error output [fedora-all]
bugzilla·2019-12-09·CVSS 6.1
CVE-2019-17632 [MEDIUM] CVE-2019-17632 jetty: generation of default unhandled error response content does not escape exception messages in stacktraces included in error output [fedora-all]
CVE-2019-17632 jetty: generation of default unhandled error response content does not escape exception messages in stacktraces included in error output [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changel
Bugzilla
CVE-2019-17632 jetty: generation of default unhandled error response content does not escape exception messages in stacktraces included in error output
bugzilla·2019-12-09·CVSS 6.1
CVE-2019-17632 [MEDIUM] CVE-2019-17632 jetty: generation of default unhandled error response content does not escape exception messages in stacktraces included in error output
CVE-2019-17632 jetty: generation of default unhandled error response content does not escape exception messages in stacktraces included in error output
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.
Reference:
https://bugs.eclipse.org/bugs/show_bug.cgi?id=553443
Discussion:
Created jetty tracking bugs for this issue:
Affects: fedora-all [bug 1781215]
---
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss Fuse 6
* Red Hat JBoss Fuse Service Works 6
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for
https://bugs.eclipse.org/bugs/show_bug.cgi?id=553443https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SAITZ27GKPD2CCNHGT2VBT4VWIBUJJNS/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://bugs.eclipse.org/bugs/show_bug.cgi?id=553443https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SAITZ27GKPD2CCNHGT2VBT4VWIBUJJNS/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2019-11-25
Published