In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.eclipse.jetty:jetty-server(Maven) | 0 | 9.2.27.v20190403 | N/A |
| org.eclipse.jetty:jetty-server(Maven) | 9.3.0 | 9.3.26.v20190403 | N/A |
| org.eclipse.jetty:jetty-server(Maven) | 9.4.0 | 9.4.16.v20190411 | N/A |
CVSS Metrics