CVE-2019-10246: Infoleak
Eclipse Jetty could allow a remote attacker to obtain sensitive information, caused by a flaw when configured for showing a listing of directory contents. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information.
Other sources
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Eclipse Jetty vulnerability?
The vulnerability ID for this Eclipse Jetty vulnerability is CVE-2019-10246.
What is the severity level of CVE-2019-10246?
The severity level of CVE-2019-10246 is medium (5.3).
Which software versions are affected by CVE-2019-10246?
Eclipse Jetty versions 9.2.27, 9.3.26, and 9.4.16 are affected by CVE-2019-10246.
How can a remote attacker exploit this vulnerability in Eclipse Jetty?
A remote attacker can exploit this vulnerability in Eclipse Jetty to obtain sensitive information by exposing the fully qualified Base Resource directory name on Windows to a remote client when the server is configured for showing a Listing of directory contents.
Are Windows servers vulnerable to CVE-2019-10246?
No, Windows servers are not vulnerable to CVE-2019-10246.