CVE-2009-4610: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to jsp/dump.jsp in the JSP Dump feature, or the (2) Name or (3) Value parameter to the default URI for the Session Dump Servlet under session/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4610?
CVE-2009-4610 has a moderate severity level due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2009-4610?
To mitigate CVE-2009-4610, it is recommended to upgrade to a non-vulnerable version of Mort Bay Jetty.
What versions of Jetty are affected by CVE-2009-4610?
CVE-2009-4610 affects Mort Bay Jetty versions 6.x and 7.0.0.
What types of attacks can CVE-2009-4610 enable?
CVE-2009-4610 can enable remote attackers to inject arbitrary web scripts or HTML through cross-site scripting (XSS) vulnerabilities.
Is there a workaround for CVE-2009-4610?
There are no known workarounds for CVE-2009-4610; upgrading is the best course of action.