CVE-2019-17632

CVE-2019-17632

Vendor The Eclipse Foundation
Product Eclipse Jetty
Weakness CWE-79 · XSS
Published November 25, 2019
Last update August 5, 2024

CVSS base score

What the vulnerability does

01Description

In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.

Key dates

02Disclosure timeline

November 25, 2019 CVE published
August 5, 2024 Record updated

Related vulnerabilities

04Related CVE