VendorsEclipsejettyany version
Vulnerabilities

Eclipse Jetty any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2022-2047
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
Published 2022-07-07 · Modified
4.0EPSS 0.013
CVE-2021-34428
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
Published 2021-06-22 · Modified
3.6EPSS 0.010
CVE-2023-36479
Jetty vulnerable to errant command quoting in CGI Servlet
Published 2023-09-15 · Analyzed
3.5EPSS 0.012
← Prev2 / 2