Known vulnerabilities in Jetty - page 3

Vendor: Eclipse
Software: Jetty
Software CPE: cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
Total vulnerabilities: 50
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Jetty Jetty is affected by 50 known vulnerabilities: 4 high, 31 medium, 15 low Critical High Medium Low

Vulnerabilities (50)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU97294 - Exposure of sensitive information to an unauthorized actor
CVE-2019-10246
CWE-200 Medium
No
No
- 16.09.2024 SB2019051138
SB2024091613
SB2025082547
and 1 more
#VU36036 - Improper input validation
CVE-2018-12545
CWE-20 Medium
No
No
- 27.03.2019 SB2019032714
SB2023020235
SB2023050520
and 4 more
#VU13530 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12536
CWE-200 Low
No
No
9.3.24.v20180605, 9.4.11.v20180605 02.07.2018 SB2018070205
SB2022032830
SB2022032831
and 8 more
#VU13529 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2017-7658
CWE-444 Low
No
No
9.2.25.v2018060, 9.3.24.v20180605, 9.4.11.v20180605 02.07.2018 SB2018070205
SB2018082001
SB2020102711
and 17 more
#VU13528 - Exposure of sensitive information to an unauthorized actor
CVE-2017-7657
CWE-200 Low
No
No
9.3.24.v20180605, 9.4.11.v20180605 02.07.2018 SB2018070205
SB2018082001
SB2022040632
and 18 more
#VU13527 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2017-7656
CWE-444 Low
No
No
9.3.24.v20180605, 9.4.11.v20180605 30.06.2018 SB2018070205
SB2018082001
SB2022041923
and 17 more
#VU13531 - Session Fixation
CVE-2018-12538
CWE-384 Low
No
No
9.4.9.v20180320 29.06.2018 SB2018070205
SB2024051717
SB2024110830
and 2 more
#VU11844 - Exposure of sensitive information to an unauthorized actor
CVE-2015-2080
CWE-200 Low
Available
No
- 16.04.2018 SB2018041212
SB2015022506
#VU9654 - Information Exposure Through Timing Discrepancy
CVE-2017-9735
CWE-208 Low
No
No
- 17.06.2017 SB2017061704
SB2021072132
SB2023042803
and 12 more
#VU340 - Improper input validation
CVE-2016-4800
CWE-20 Medium
No
No
- 20.08.2016 SB2016060101
SB2023011129
SB2024021519


Showing elements 41 - 60 out of 50