Information Exposure The advisory has been revoked - it doesn't affect any version of package org.eclipse.jetty:jetty-util  (opens in a new tab)


Threat Intelligence

EPSS
3.36% (88th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGECLIPSEJETTY-174480
  • published22 Apr 2019
  • disclosed22 Apr 2019
  • creditUnknown

Introduced: 22 Apr 2019

CVE-2019-10247  (opens in a new tab)
CWE-213  (opens in a new tab)

Amendment

This was deemed not a vulnerability.

Overview

org.eclipse.jetty:jetty-util is a Web Container & Clients - supports HTTP/2, HTTP/1.1, HTTP/1.0, websocket, servlets, and more.

Affected versions of this package are vulnerable to Information Exposure. The configuration of a Jetty server may be leaked as part of a HTTP 404 response. This is due to the DefaultHandler class producing an error page during an exception.