First published: Wed Nov 06 2019(Updated: )
Dump Servlet information leak in jetty before 6.1.22.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/jetty | ||
Mortbay Jetty | <6.1.22 | |
Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-5045 is a vulnerability in Jetty web server versions prior to 6.1.22 that allows an attacker to leak sensitive information through a dump servlet.
Jetty web server versions prior to 6.1.22 and Debian Linux version 8.0 with the Jetty package are affected by CVE-2009-5045.
CVE-2009-5045 has a severity rating of 7.5 (high).
To fix CVE-2009-5045, upgrade to Jetty version 6.1.22 or later if you are using Jetty web server, or apply the necessary security updates if you are using Debian Linux 8.0 with the Jetty package.
You can find more information about CVE-2009-5045 at the following references: [1] https://security-tracker.debian.org/tracker/CVE-2009-5045, [2] http://www.ush.it/team/ush/hack-jetty6x7x/jetty-adv.txt, [3] https://www.openwall.com/lists/oss-security/2011/01/14/2