First published: Tue Apr 28 2009(Updated: )
Common Vulnerabilities and Exposures assigned the identifiers <a href="https://access.redhat.com/security/cve/CVE-2009-1523">CVE-2009-1523</a> and <a href="https://access.redhat.com/security/cve/CVE-2009-1524">CVE-2009-1524</a> to the following vulnerabilities: Name: <a href="https://access.redhat.com/security/cve/CVE-2009-1523">CVE-2009-1523</a> URL: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1523">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1523</a> Assigned: 20090505 Reference: CONFIRM: <a href="http://jira.codehaus.org/browse/JETTY-1004">http://jira.codehaus.org/browse/JETTY-1004</a> Reference: CONFIRM: <a href="http://www.kb.cert.org/vuls/id/CRDY-7RKQCY">http://www.kb.cert.org/vuls/id/CRDY-7RKQCY</a> Reference: CERT-VN:VU#402580 Reference: URL: <a href="http://www.kb.cert.org/vuls/id/402580">http://www.kb.cert.org/vuls/id/402580</a> Reference: BID:34800 Reference: URL: <a href="http://www.securityfocus.com/bid/34800">http://www.securityfocus.com/bid/34800</a> Reference: SECUNIA:34975 Reference: URL: <a href="http://secunia.com/advisories/34975">http://secunia.com/advisories/34975</a> Directory traversal vulnerability in the HTTP server in Mort Bay Jetty before 6.1.17, and 7.0.0.M2 and earlier 7.x versions, allows remote attackers to access arbitrary files via directory traversal sequences in the URI. Name: <a href="https://access.redhat.com/security/cve/CVE-2009-1524">CVE-2009-1524</a> URL: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1524">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1524</a> Assigned: 20090505 Reference: CONFIRM: <a href="http://jira.codehaus.org/browse/JETTY-980">http://jira.codehaus.org/browse/JETTY-980</a> Reference: BID:34800 Reference: URL: <a href="http://www.securityfocus.com/bid/34800">http://www.securityfocus.com/bid/34800</a> Reference: SECUNIA:34975 Reference: URL: <a href="http://secunia.com/advisories/34975">http://secunia.com/advisories/34975</a> Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) character. Note: it is unclear whether or not this affects jetty 5.x, which is the version that is included in Fedora.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.mortbay.jetty:jetty | >=7.0.0.M0<7.0.0.M2 | 7.0.0.M2 |
maven/org.mortbay.jetty:jetty | <6.1.17 | 6.1.17 |
Eclipse Jetty | <=6.1.16 | |
Eclipse Jetty | <=7.0.0 | |
Eclipse Jetty | =1.0 | |
Eclipse Jetty | =1.0.1 | |
Eclipse Jetty | =1.1 | |
Eclipse Jetty | =1.1.1 | |
Eclipse Jetty | =1.2.0 | |
Eclipse Jetty | =1.3.0 | |
Eclipse Jetty | =1.3.1 | |
Eclipse Jetty | =1.3.2 | |
Eclipse Jetty | =1.3.3 | |
Eclipse Jetty | =1.3.4 | |
Eclipse Jetty | =1.3.5 | |
Eclipse Jetty | =2.0-alpha1 | |
Eclipse Jetty | =2.0-alpha2 | |
Eclipse Jetty | =2.0-beta1 | |
Eclipse Jetty | =2.0-beta2 | |
Eclipse Jetty | =2.0.0 | |
Eclipse Jetty | =2.0.1 | |
Eclipse Jetty | =2.0.2 | |
Eclipse Jetty | =2.0.3 | |
Eclipse Jetty | =2.0.4 | |
Eclipse Jetty | =2.0.5 | |
Eclipse Jetty | =2.1.0 | |
Eclipse Jetty | =2.1.1 | |
Eclipse Jetty | =2.1.2 | |
Eclipse Jetty | =2.1.3 | |
Eclipse Jetty | =2.1.4 | |
Eclipse Jetty | =2.1.5 | |
Eclipse Jetty | =2.1.6 | |
Eclipse Jetty | =2.1.7 | |
Eclipse Jetty | =2.1.b0 | |
Eclipse Jetty | =2.1.b1 | |
Eclipse Jetty | =2.2-alpha0 | |
Eclipse Jetty | =2.2-alpha1 | |
Eclipse Jetty | =2.2-beta0 | |
Eclipse Jetty | =2.2-beta1 | |
Eclipse Jetty | =2.2-beta2 | |
Eclipse Jetty | =2.2-beta3 | |
Eclipse Jetty | =2.2-beta4 | |
Eclipse Jetty | =2.2.0 | |
Eclipse Jetty | =2.2.1 | |
Eclipse Jetty | =2.2.2 | |
Eclipse Jetty | =2.2.3 | |
Eclipse Jetty | =2.2.4 | |
Eclipse Jetty | =2.2.5 | |
Eclipse Jetty | =2.2.6 | |
Eclipse Jetty | =2.2.7 | |
Eclipse Jetty | =2.2.8 | |
Eclipse Jetty | =2.3.0 | |
Eclipse Jetty | =2.3.0a | |
Eclipse Jetty | =2.3.1 | |
Eclipse Jetty | =2.3.2 | |
Eclipse Jetty | =2.3.3 | |
Eclipse Jetty | =2.3.4 | |
Eclipse Jetty | =2.3.5 | |
Eclipse Jetty | =2.4.0 | |
Eclipse Jetty | =2.4.1 | |
Eclipse Jetty | =2.4.2 | |
Eclipse Jetty | =2.4.3 | |
Eclipse Jetty | =2.4.4 | |
Eclipse Jetty | =2.4.5 | |
Eclipse Jetty | =2.4.6 | |
Eclipse Jetty | =2.4.7 | |
Eclipse Jetty | =2.4.8 | |
Eclipse Jetty | =2.4.9 | |
Eclipse Jetty | =3.0.0 | |
Eclipse Jetty | =3.0.0-rc1 | |
Eclipse Jetty | =3.0.0-rc2 | |
Eclipse Jetty | =3.0.0-rc3 | |
Eclipse Jetty | =3.0.0-rc4 | |
Eclipse Jetty | =3.0.0-rc5 | |
Eclipse Jetty | =3.0.0-rc6 | |
Eclipse Jetty | =3.0.0-rc7 | |
Eclipse Jetty | =3.0.0-rc8 | |
Eclipse Jetty | =3.0.1 | |
Eclipse Jetty | =3.0.2 | |
Eclipse Jetty | =3.0.3 | |
Eclipse Jetty | =3.0.4 | |
Eclipse Jetty | =3.0.5 | |
Eclipse Jetty | =3.0.6 | |
Eclipse Jetty | =3.0.a0 | |
Eclipse Jetty | =3.0.a1 | |
Eclipse Jetty | =3.0.a2 | |
Eclipse Jetty | =3.0.a3 | |
Eclipse Jetty | =3.0.a4 | |
Eclipse Jetty | =3.0.a5 | |
Eclipse Jetty | =3.0.a6 | |
Eclipse Jetty | =3.0.a7 | |
Eclipse Jetty | =3.0.a8 | |
Eclipse Jetty | =3.0.a9 | |
Eclipse Jetty | =3.0.a90 | |
Eclipse Jetty | =3.0.a91 | |
Eclipse Jetty | =3.0.a92 | |
Eclipse Jetty | =3.0.a93 | |
Eclipse Jetty | =3.0.a94 | |
Eclipse Jetty | =3.0.a95 | |
Eclipse Jetty | =3.0.a96 | |
Eclipse Jetty | =3.0.a97 | |
Eclipse Jetty | =3.0.a98 | |
Eclipse Jetty | =3.0.a99 | |
Eclipse Jetty | =3.0.b01 | |
Eclipse Jetty | =3.0.b02 | |
Eclipse Jetty | =3.0.b03 | |
Eclipse Jetty | =3.0.b04 | |
Eclipse Jetty | =3.0.b05 | |
Eclipse Jetty | =3.1-rc0 | |
Eclipse Jetty | =3.1-rc1 | |
Eclipse Jetty | =3.1-rc2 | |
Eclipse Jetty | =3.1-rc3 | |
Eclipse Jetty | =3.1-rc4 | |
Eclipse Jetty | =3.1-rc5 | |
Eclipse Jetty | =3.1-rc6 | |
Eclipse Jetty | =3.1-rc7 | |
Eclipse Jetty | =3.1-rc8 | |
Eclipse Jetty | =3.1-rc9 | |
Eclipse Jetty | =3.1.0 | |
Eclipse Jetty | =3.1.1 | |
Eclipse Jetty | =3.1.2 | |
Eclipse Jetty | =3.1.3 | |
Eclipse Jetty | =3.1.4 | |
Eclipse Jetty | =3.1.5 | |
Eclipse Jetty | =3.1.6 | |
Eclipse Jetty | =3.1.7 | |
Eclipse Jetty | =3.1.8 | |
Eclipse Jetty | =3.1.9 | |
Eclipse Jetty | =4.0-rc1 | |
Eclipse Jetty | =4.0-rc2 | |
Eclipse Jetty | =4.0-rc3 | |
Eclipse Jetty | =4.0.0 | |
Eclipse Jetty | =4.0.1 | |
Eclipse Jetty | =4.0.1-rc0 | |
Eclipse Jetty | =4.0.1-rc1 | |
Eclipse Jetty | =4.0.1-rc2 | |
Eclipse Jetty | =4.0.2 | |
Eclipse Jetty | =4.0.3 | |
Eclipse Jetty | =4.0.4 | |
Eclipse Jetty | =4.0.5 | |
Eclipse Jetty | =4.0.6 | |
Eclipse Jetty | =4.0.b0 | |
Eclipse Jetty | =4.0.b1 | |
Eclipse Jetty | =4.0.b2 | |
Eclipse Jetty | =4.0.d0 | |
Eclipse Jetty | =4.0.d1 | |
Eclipse Jetty | =4.0.d2 | |
Eclipse Jetty | =4.0.d3 | |
Eclipse Jetty | =4.0.d4 | |
Eclipse Jetty | =4.1.0 | |
Eclipse Jetty | =4.1.0-rc0 | |
Eclipse Jetty | =4.1.0-rc1 | |
Eclipse Jetty | =4.1.0-rc2 | |
Eclipse Jetty | =4.1.0-rc3 | |
Eclipse Jetty | =4.1.0-rc4 | |
Eclipse Jetty | =4.1.0-rc5 | |
Eclipse Jetty | =4.1.0-rc6 | |
Eclipse Jetty | =4.1.1 | |
Eclipse Jetty | =4.1.2 | |
Eclipse Jetty | =4.1.3 | |
Eclipse Jetty | =4.1.4 | |
Eclipse Jetty | =4.1.b0 | |
Eclipse Jetty | =4.1.b1 | |
Eclipse Jetty | =4.1.d0 | |
Eclipse Jetty | =4.1.d1 | |
Eclipse Jetty | =4.1.d2 | |
Eclipse Jetty | =4.2.0 | |
Eclipse Jetty | =4.2.0-beta0 | |
Eclipse Jetty | =4.2.0-rc0 | |
Eclipse Jetty | =4.2.0-rc1 | |
Eclipse Jetty | =4.2.1 | |
Eclipse Jetty | =4.2.2 | |
Eclipse Jetty | =4.2.3 | |
Eclipse Jetty | =4.2.4 | |
Eclipse Jetty | =4.2.4-rc0 | |
Eclipse Jetty | =4.2.5 | |
Eclipse Jetty | =4.2.6 | |
Eclipse Jetty | =4.2.7 | |
Eclipse Jetty | =4.2.8_01 | |
Eclipse Jetty | =4.2.9 | |
Eclipse Jetty | =4.2.9-rc1 | |
Eclipse Jetty | =4.2.9-rc2 | |
Eclipse Jetty | =4.2.10 | |
Eclipse Jetty | =4.2.10-pre0 | |
Eclipse Jetty | =4.2.10-pre1 | |
Eclipse Jetty | =4.2.10-pre2 | |
Eclipse Jetty | =4.2.12 | |
Eclipse Jetty | =4.2.14 | |
Eclipse Jetty | =4.2.14-rc0 | |
Eclipse Jetty | =4.2.14-rc1 | |
Eclipse Jetty | =4.2.15 | |
Eclipse Jetty | =4.2.15-rc0 | |
Eclipse Jetty | =4.2.16 | |
Eclipse Jetty | =4.2.17 | |
Eclipse Jetty | =4.2.18 | |
Eclipse Jetty | =4.2.19 | |
Eclipse Jetty | =4.2.20 | |
Eclipse Jetty | =4.2.20-rc0 | |
Eclipse Jetty | =4.2.21 | |
Eclipse Jetty | =4.2.22 | |
Eclipse Jetty | =4.2.23 | |
Eclipse Jetty | =4.2.23-rc0 | |
Eclipse Jetty | =4.2.24 | |
Eclipse Jetty | =4.2.24-rc0 | |
Eclipse Jetty | =4.2.24-rc1 | |
Eclipse Jetty | =4.2.25 | |
Eclipse Jetty | =4.2.26 | |
Eclipse Jetty | =4.2.27 | |
Eclipse Jetty | =5.0-alpha0 | |
Eclipse Jetty | =5.0-alpha1 | |
Eclipse Jetty | =5.0-alpha2 | |
Eclipse Jetty | =5.0-alpha3 | |
Eclipse Jetty | =5.0-beta0 | |
Eclipse Jetty | =5.0-beta1 | |
Eclipse Jetty | =5.0-beta2 | |
Eclipse Jetty | =5.0-rc1 | |
Eclipse Jetty | =5.0-rc2 | |
Eclipse Jetty | =5.0-rc3 | |
Eclipse Jetty | =5.0-rc4 | |
Eclipse Jetty | =5.0.0 | |
Eclipse Jetty | =5.0.0-rc0 | |
Eclipse Jetty | =5.1-rc0 | |
Eclipse Jetty | =5.1-rc1 | |
Eclipse Jetty | =5.1.0 | |
Eclipse Jetty | =5.1.1 | |
Eclipse Jetty | =5.1.1-rc0 | |
Eclipse Jetty | =5.1.1-rc1 | |
Eclipse Jetty | =5.1.2 | |
Eclipse Jetty | =5.1.2-pre0 | |
Eclipse Jetty | =5.1.3 | |
Eclipse Jetty | =5.1.3-rc0 | |
Eclipse Jetty | =5.1.3-rc1 | |
Eclipse Jetty | =5.1.3-rc2 | |
Eclipse Jetty | =5.1.3-rc3 | |
Eclipse Jetty | =5.1.3-rc4 | |
Eclipse Jetty | =5.1.4 | |
Eclipse Jetty | =5.1.4-rc0 | |
Eclipse Jetty | =5.1.5 | |
Eclipse Jetty | =5.1.5-rc0 | |
Eclipse Jetty | =5.1.5-rc1 | |
Eclipse Jetty | =5.1.5-rc2 | |
Eclipse Jetty | =5.1.6 | |
Eclipse Jetty | =5.1.7 | |
Eclipse Jetty | =5.1.7-rc0 | |
Eclipse Jetty | =5.1.8 | |
Eclipse Jetty | =5.1.9 | |
Eclipse Jetty | =5.1.10 | |
Eclipse Jetty | =5.1.11 | |
Eclipse Jetty | =5.1.11-rc0 | |
Eclipse Jetty | =5.1.12 | |
Eclipse Jetty | =5.1.13 | |
Eclipse Jetty | =5.1.14 | |
Eclipse Jetty | =6.0.0 | |
Eclipse Jetty | =6.0.0-alpha0 | |
Eclipse Jetty | =6.0.0-alpha1 | |
Eclipse Jetty | =6.0.0-alpha2 | |
Eclipse Jetty | =6.0.0-alpha3 | |
Eclipse Jetty | =6.0.0-beta0 | |
Eclipse Jetty | =6.0.0-beta1 | |
Eclipse Jetty | =6.0.0-beta10 | |
Eclipse Jetty | =6.0.0-beta11 | |
Eclipse Jetty | =6.0.0-beta12 | |
Eclipse Jetty | =6.0.0-beta14 | |
Eclipse Jetty | =6.0.0-beta15 | |
Eclipse Jetty | =6.0.0-beta16 | |
Eclipse Jetty | =6.0.0-beta17 | |
Eclipse Jetty | =6.0.0-beta2 | |
Eclipse Jetty | =6.0.0-beta3 | |
Eclipse Jetty | =6.0.0-beta4 | |
Eclipse Jetty | =6.0.0-beta5 | |
Eclipse Jetty | =6.0.0-beta6 | |
Eclipse Jetty | =6.0.0-beta7 | |
Eclipse Jetty | =6.0.0-beta8 | |
Eclipse Jetty | =6.0.0-beta9 | |
Eclipse Jetty | =6.0.0-betax | |
Eclipse Jetty | =6.0.0-rc0 | |
Eclipse Jetty | =6.0.0-rc1 | |
Eclipse Jetty | =6.0.0-rc2 | |
Eclipse Jetty | =6.0.0-rc3 | |
Eclipse Jetty | =6.0.0-rc4 | |
Eclipse Jetty | =6.0.1 | |
Eclipse Jetty | =6.0.2 | |
Eclipse Jetty | =6.1.0 | |
Eclipse Jetty | =6.1.0-pre0 | |
Eclipse Jetty | =6.1.0-pre1 | |
Eclipse Jetty | =6.1.0-pre2 | |
Eclipse Jetty | =6.1.0-pre3 | |
Eclipse Jetty | =6.1.0-rc0 | |
Eclipse Jetty | =6.1.0-rc1 | |
Eclipse Jetty | =6.1.0-rc2 | |
Eclipse Jetty | =6.1.0-rc3 | |
Eclipse Jetty | =6.1.1 | |
Eclipse Jetty | =6.1.1-rc0 | |
Eclipse Jetty | =6.1.2 | |
Eclipse Jetty | =6.1.2-pre0 | |
Eclipse Jetty | =6.1.2-pre1 | |
Eclipse Jetty | =6.1.2-rc0 | |
Eclipse Jetty | =6.1.2-rc1 | |
Eclipse Jetty | =6.1.2-rc2 | |
Eclipse Jetty | =6.1.2-rc3 | |
Eclipse Jetty | =6.1.2-rc4 | |
Eclipse Jetty | =6.1.2-rc5 | |
Eclipse Jetty | =6.1.3 | |
Eclipse Jetty | =6.1.4 | |
Eclipse Jetty | =6.1.4-rc0 | |
Eclipse Jetty | =6.1.4-rc1 | |
Eclipse Jetty | =6.1.5 | |
Eclipse Jetty | =6.1.5-rc0 | |
Eclipse Jetty | =6.1.6 | |
Eclipse Jetty | =6.1.6-rc0 | |
Eclipse Jetty | =6.1.6-rc1 | |
Eclipse Jetty | =6.1.7 | |
Eclipse Jetty | =6.1.8 | |
Eclipse Jetty | =6.1.9 | |
Eclipse Jetty | =6.1.10 | |
Eclipse Jetty | =6.1.11 | |
Eclipse Jetty | =6.1.12 | |
Eclipse Jetty | =6.1.12-rc1 | |
Eclipse Jetty | =6.1.12-rc2 | |
Eclipse Jetty | =6.1.12-rc3 | |
Eclipse Jetty | =6.1.12-rc4 | |
Eclipse Jetty | =6.1.12-rc5 | |
Eclipse Jetty | =6.1.14 | |
Eclipse Jetty | =6.1.15 | |
Eclipse Jetty | =6.1.15-pre0 | |
Eclipse Jetty | =6.1.15-rc2 | |
Eclipse Jetty | =6.1.15-rc3 | |
Eclipse Jetty | =6.1.15-rc4 | |
Eclipse Jetty | =6.1.15-rc5 | |
Eclipse Jetty | =7.0.0 | |
Eclipse Jetty | =7.0.0-m1 | |
Eclipse Jetty | =7.0.0-pre0 | |
Eclipse Jetty | =7.0.0-pre1 | |
Eclipse Jetty | =7.0.0-pre3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1523 has been assigned a medium severity rating due to its potential for unauthorized access.
To fix CVE-2009-1523, update the affected versions of the Jetty server to version 6.1.17 or later.
CVE-2009-1523 affects specific versions of the Eclipse Jetty server, including versions up to 7.0.0.M2.
CVE-2009-1523 is a vulnerability that can allow remote attackers to bypass access controls.
CVE-2009-1523 was disclosed in May 2009.