Unescaped exception messages in error responses in Jetty
Moderate severity
GitHub Reviewed
Published
Dec 2, 2019
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Package
Affected versions
= 9.4.21.v20190926
= 9.4.22.v20191022
= 9.4.23.v20191118
Patched versions
9.4.24.v20191120
9.4.24.v20191120
9.4.24.v20191120
Description
Published by the National Vulnerability Database
Nov 25, 2019
Reviewed
Dec 2, 2019
Published to the GitHub Advisory Database
Dec 2, 2019
Last updated
Feb 1, 2023
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.
References