First published: Wed Jan 13 2010(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Jetty | =6.1.0 | |
Eclipse Jetty | =6.1.0-pre0 | |
Eclipse Jetty | =6.1.0-pre1 | |
Eclipse Jetty | =6.1.0-pre2 | |
Eclipse Jetty | =6.1.0-pre3 | |
Eclipse Jetty | =6.1.0-rc0 | |
Eclipse Jetty | =6.1.0-rc1 | |
Eclipse Jetty | =6.1.0-rc2 | |
Eclipse Jetty | =6.1.0-rc3 | |
Eclipse Jetty | =6.1.1 | |
Eclipse Jetty | =6.1.1-rc0 | |
Eclipse Jetty | =6.1.2 | |
Eclipse Jetty | =6.1.2-pre0 | |
Eclipse Jetty | =6.1.2-pre1 | |
Eclipse Jetty | =6.1.2-rc0 | |
Eclipse Jetty | =6.1.2-rc1 | |
Eclipse Jetty | =6.1.2-rc2 | |
Eclipse Jetty | =6.1.2-rc3 | |
Eclipse Jetty | =6.1.2-rc4 | |
Eclipse Jetty | =6.1.2-rc5 | |
Eclipse Jetty | =6.1.3 | |
Eclipse Jetty | =6.1.4 | |
Eclipse Jetty | =6.1.4-rc0 | |
Eclipse Jetty | =6.1.4-rc1 | |
Eclipse Jetty | =6.1.5 | |
Eclipse Jetty | =6.1.5-rc0 | |
Eclipse Jetty | =6.1.6 | |
Eclipse Jetty | =6.1.6-rc0 | |
Eclipse Jetty | =6.1.6-rc1 | |
Eclipse Jetty | =6.1.7 | |
Eclipse Jetty | =6.1.8 | |
Eclipse Jetty | =6.1.9 | |
Eclipse Jetty | =6.1.10 | |
Eclipse Jetty | =6.1.11 | |
Eclipse Jetty | =6.1.12 | |
Eclipse Jetty | =6.1.12-rc1 | |
Eclipse Jetty | =6.1.12-rc2 | |
Eclipse Jetty | =6.1.12-rc3 | |
Eclipse Jetty | =6.1.12-rc4 | |
Eclipse Jetty | =6.1.12-rc5 | |
Eclipse Jetty | =6.1.14 | |
Eclipse Jetty | =6.1.15 | |
Eclipse Jetty | =6.1.15-pre0 | |
Eclipse Jetty | =6.1.15-rc2 | |
Eclipse Jetty | =6.1.15-rc3 | |
Eclipse Jetty | =6.1.15-rc4 | |
Eclipse Jetty | =6.1.15-rc5 | |
Eclipse Jetty | =6.1.16 | |
Eclipse Jetty | =6.1.19 | |
Eclipse Jetty | =6.1.20 | |
Eclipse Jetty | =6.1.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4612 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To mitigate CVE-2009-4612, upgrade to a patched version of Mort Bay Jetty that resolves the XSS vulnerabilities.
CVE-2009-4612 affects Mort Bay Jetty versions from 6.1.0 to 6.1.21.
CVE-2009-4612 allows remote attackers to execute arbitrary HTML or web scripts via cross-site scripting.
CVE-2009-4612 is considered a server-side vulnerability as it affects the web application server handling requests.