CVE-2009-5048: XSS
Published Nov 6, 2019
·Updated
Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.
Affected Software
2 affected components
debian/jetty
Mortbay Jetty<=6.1.20
Event History
Nov 6, 2019
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
Description
Aug 7, 2024
Data Sourced
via Debian·07:35 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-5048?
CVE-2009-5048 is classified as a moderate severity stored XSS vulnerability in Jetty.
2
How do I fix CVE-2009-5048?
To fix CVE-2009-5048, upgrade Jetty to a version later than 6.1.20.
3
What versions of Jetty are affected by CVE-2009-5048?
CVE-2009-5048 affects Jetty versions up to and including 6.1.20.
4
Can CVE-2009-5048 be exploited remotely?
Yes, CVE-2009-5048 can be exploited remotely due to the nature of stored XSS.
5
What impact does CVE-2009-5048 have on security?
CVE-2009-5048 allows attackers to execute arbitrary scripts in the context of a user's browser.