CVE-2009-5046: XSS
Published Nov 6, 2019
·Updated
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.
Affected Software
3 affected components
debian/jetty
Eclipse Jetty<6.1.22
Debian Debian Linux=8.0
Event History
Nov 6, 2019
CVE Published
via MITRE·07:57 PM
Data Sourced
via MITRE·07:57 PM
Description
Aug 7, 2024
Data Sourced
via Debian·07:35 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2009-5046?
CVE-2009-5046 is a vulnerability in Jetty before version 6.1.22 that allows for XSS (Cross-Site Scripting) attacks through JSP Dump and Session Dump Servlets.
2
How severe is CVE-2009-5046?
CVE-2009-5046 has a severity keyword of 'medium' and a severity value of 6.1.
3
Which software versions are affected by CVE-2009-5046?
Jetty versions before 6.1.22 and Debian Linux version 8.0 are affected by CVE-2009-5046.
4
How can I fix CVE-2009-5046?
To fix CVE-2009-5046, update your Jetty server to version 6.1.22 or later.
5
Where can I find more information about CVE-2009-5046?
You can find more information about CVE-2009-5046 in the following references: http://www.ush.it/team/ush/hack-jetty6x7x/jetty-adv.txt, https://security-tracker.debian.org/tracker/CVE-2009-5046, https://www.openwall.com/lists/oss-security/2011/01/14/2.