In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "5.15.9"
},
{
"introduced": "0"
},
{
"last_affected": "5.2.0"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "9.2.0-20140523"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.0-20140526"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.0-maintenance_0"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.0-maintenance_1"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.0-rc0"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.1-20140609"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.2-20140723"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.3-20140905"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.4-20141103"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.5-20141112"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.6-20141203"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.6-20141205"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.7-20150116"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.8-20150217"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.9-20150224"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.10-20150310"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.11-20150528"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.11-20150529"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.11-maintenance_0"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.12-20150709"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.12-maintenance_0"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.13-20150730"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.14-20151106"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.15-20160210"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.16-20160407"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.16-20160414"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.17-20160517"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.18-20160721"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.19-20160908"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.20-20161216"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.21-20170120"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.22-20170606"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.23-20171218"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.24-20180105"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.25-20180606"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.26-20180806"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-20150601"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-20150608"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-20150612"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-maintenance0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-maintenance1"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-maintenance2"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-rc0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.1-20150714"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.2-20150730"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.3-20150825"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.3-20150827"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.4-20151005"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.4-20151007"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.4-rc0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.4-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.5-20151012"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.6-20151106"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.7-20160115"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.7-rc0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.7-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.8-20160311"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.8-20160314"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.8-rc0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.9-20160517"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.9-maintenance_0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.9-maintenance_1"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.10-20160621"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.10-maintenance_0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.11-20160721"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.11-maintenance_0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.12-20160915"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.13-20161014"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.13-maintenance_0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.14-20161028"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.15-20161220"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.16-20170119"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.16-20170120"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.17-20170317"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.17-rc0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.18-20170406"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.19-20170502"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.20-20170531"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.21-20170918"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.21-maintenance_0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.21-rc0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.22-20171030"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.23-20180228"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.24-20180605"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.25-20180904"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.0-20161207"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.0-20161208"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.0-20180619"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.0-maintenance_0"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.0-maintenance_1"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.0-rc0"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.1-20170120"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.1-20180619"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.2-20170220"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.2-20180619"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.3-20170317"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.3-20180619"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.4-20170410"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.4-20170414"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.4-20180619"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.5-20170502"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.5-20180619"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.6-20170531"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.6-20180619"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.7-20170914"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.7-20180619"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.7-rc0"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.8-20171121"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.8-20180619"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.9-20180320"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.10-20180503"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.10-rc0"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.10-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.11-20180605"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.12-20180830"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.12-rc0"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.12-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.12-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.13-20181111"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.14-20181114"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.15-20190215"
},
{
"introduced": "0"
},
{
"last_affected": "9.0"
},
{
"introduced": "0"
},
{
"last_affected": "10.0"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.16.0"
}
]
},
{
"events": [
{
"introduced": "11.5.0"
},
{
"last_affected": "11.7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.2.0.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.1.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "18c"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.0"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10241.json"