Cross-site scripting in Jetty - CVE-2019-10241
Published: March 23, 2020
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Cloudera Observability with IBM
CloudLink
Traffix SDC
AMQ Broker
BIG-IQ Centralized Management
jetty9 (Debian package)
jetty-osgi-boot-jsp
jetty-plus
jetty-quickstart
jetty-jsp
jetty
jetty-javadoc
jetty-http
jetty-jmx
jetty-websocket-client
jetty-jaspi
jetty-osgi-alpn
jetty-project
jetty-cdi
jetty-alpn-server
jetty-unixsocket
jetty-javax-websocket-server-impl
jetty-alpn-client
jetty-javax-websocket-client-impl
jetty-maven-plugin
jetty-deploy
jetty-proxy
jetty-server
jetty-http2-server
jetty-security
jetty-websocket-servlet
jetty-xml
jetty-http2-http-client-transport
jetty-http2-client
jetty-jndi
jetty-fcgi-client
jetty-osgi-boot
jetty-nosql
jetty-http2-common
jetty-http2-hpack
jetty-rewrite
jetty-start
jetty-websocket-server
jetty-continuation
jetty-jspc-maven-plugin
jetty-client
jetty-servlets
jetty-servlet
jetty-jstl
jetty-http-spi
jetty-util
jetty-io
jetty-infinispan
jetty-fcgi-server
jetty-websocket-api
jetty-util-ajax
jetty-annotations
jetty-spring
jetty-websocket-common
jetty-osgi-boot-warurl
jetty-webapp
jetty-httpservice
jetty-ant
jetty-jaas
Opensuse
openEuler
IBM Process Mining
IBM Cloud Application Performance Management (APM)
IBM Spectrum Protect Storage Agent
IBM Security Verify Governance
Operational Decision Manager
IBM Cognos Analytics
IBM Cognos Command Center
How to mitigate CVE-2019-10241
Traffix SDC - update to 5.1.0
AMQ Broker - addressed in versions 7.4.3, 7.6
BIG-IQ Centralized Management - update to 7.1.0
jetty9 (Debian package) - update to 9.4.16-0+deb10u1
IBM Process Mining - update to 1.12.0.4
CloudLink - update to 8.0-3.10.5.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Spectrum Protect Storage Agent - update to 8.1.19
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
jetty-osgi-boot-jsp - update to 9.4.16-1
jetty-plus - update to 9.4.16-1
jetty-quickstart - update to 9.4.16-1
jetty-jsp - update to 9.4.16-1
jetty - update to 9.4.16-1
jetty-javadoc - update to 9.4.16-1
jetty-http - update to 9.4.16-1
jetty-jmx - update to 9.4.16-1
jetty-websocket-client - update to 9.4.16-1
jetty-jaspi - update to 9.4.16-1
jetty-osgi-alpn - update to 9.4.16-1
jetty-project - update to 9.4.16-1
jetty-cdi - update to 9.4.16-1
jetty-alpn-server - update to 9.4.16-1
jetty-unixsocket - update to 9.4.16-1
jetty-javax-websocket-server-impl - update to 9.4.16-1
jetty-alpn-client - update to 9.4.16-1
jetty-javax-websocket-client-impl - update to 9.4.16-1
jetty-maven-plugin - update to 9.4.16-1
jetty-deploy - update to 9.4.16-1
jetty-proxy - update to 9.4.16-1
jetty-server - update to 9.4.16-1
jetty-http2-server - update to 9.4.16-1
jetty-security - update to 9.4.16-1
jetty-websocket-servlet - update to 9.4.16-1
jetty-xml - update to 9.4.16-1
jetty-http2-http-client-transport - update to 9.4.16-1
jetty-http2-client - update to 9.4.16-1
jetty-jndi - update to 9.4.16-1
jetty-fcgi-client - update to 9.4.16-1
jetty-osgi-boot - update to 9.4.16-1
jetty-nosql - update to 9.4.16-1
jetty-http2-common - update to 9.4.16-1
jetty-http2-hpack - update to 9.4.16-1
jetty-rewrite - update to 9.4.16-1
jetty-start - update to 9.4.16-1
jetty-websocket-server - update to 9.4.16-1
jetty-continuation - update to 9.4.16-1
jetty-jspc-maven-plugin - update to 9.4.16-1
jetty-client - update to 9.4.16-1
jetty-servlets - update to 9.4.16-1
jetty-servlet - update to 9.4.16-1
jetty-jstl - update to 9.4.16-1
jetty-http-spi - update to 9.4.16-1
jetty-util - update to 9.4.16-1
jetty-io - update to 9.4.16-1
jetty-infinispan - update to 9.4.16-1
jetty-fcgi-server - update to 9.4.16-1
jetty-websocket-api - update to 9.4.16-1
jetty-util-ajax - update to 9.4.16-1
jetty-annotations - update to 9.4.16-1
jetty-spring - update to 9.4.16-1
jetty-websocket-common - update to 9.4.16-1
jetty-osgi-boot-warurl - update to 9.4.16-1
jetty-webapp - update to 9.4.16-1
jetty-httpservice - update to 9.4.16-1
jetty-ant - update to 9.4.16-1
jetty-jaas - update to 9.4.16-1
IBM Security Verify Governance - update to 10.0.1.0.3
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4
External References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=546121
- https://lists.apache.org/thread.html/01e004c3f7c7365863a27e7038b7f32dae56ccf3a496b277c9b7f7b6@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/464892b514c029dfc0c8656a93e1c0de983c473df70fdadbd224e09f@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/8bff534863c7aaf09bb17c3d0532777258dd3a5c7ddda34198cc2742@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/ac51944aef91dd5006b8510b0bef337adaccfe962fb90e7af9c22db4@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/bcfb37bfba7b3d7e9c7808b5e5a38a98d6bb714d52cf5162bdd48e32@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/d7c4a664a34853f57c2163ab562f39802df5cf809523ea40c97289c1@%3Cdev.kafka.apache.org%3E
- https://security.netapp.com/advisory/ntap-20190509-0003/
Related Security Bulletins
- Multiple vulnerabilities in Red Hat AMQ Broker
- OpenSUSE Linux update for SUSE Manager Client Tools
- XSS in BIG-IQ Centralized Management and Traffix SDC
- Debian update for jetty9
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in Dell CloudLink
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Application Performance Management
- openEuler 20.03 LTS SP3 update for jetty
- openEuler 20.03 LTS SP1 update for jetty
- openEuler 22.03 LTS update for jetty
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in AMQ Broker 7.4
- Multiple vulnerabilities in IBM Cloudera Observability on Premises with IBM