The Eclipse Foundation Eclipse Jetty vulnerabilities
22 known vulnerabilities affecting the_eclipse_foundation/eclipse_jetty.
Total CVEs
22
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH7MEDIUM9LOW3
Vulnerabilities
Page 2 of 2
CVE-2021-34428P4LOWCVSS 3.5≥ 9.0.0, < unspecified≥ unspecified, ≤ 9.4.40+2 more2021-06-22
CVE-2021-34428 [LOW] CWE-613 CVE-2021-34428: For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the Sessi
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application use
nvd
CVE-2022-2047P4LOWCVSS 2.7≥ 9.4.0, < unspecified≥ unspecified, ≤ 9.4.46+2 more2022-07-07
CVE-2022-2047 [LOW] CWE-20 CVE-2022-2047: In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
nvd
← Previous2 / 2