Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.1 Maven

Unescaped exception messages in error responses in Jetty

GHSA-5h9j-q6j2-253f · CVE-2019-17632

Published · Modified

Description

In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.

Ready to move

Start Securing

Free, no credit card | First findings in minutes