CVE-2019-10247 is an information disclosure vulnerability affecting Eclipse Jetty versions 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, as well as products like Debian, NetApp, and Oracle that utilize these Jetty versions. The vulnerability allows an unauthenticated attacker to discover the server's fully qualified directory base resource location through 404 error messages. Rated Medium with a CVSS score of 5.3, this flaw has low impact, as it only leaks directory information and does not allow for data modification or denial of service. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.1.0CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:8.1.0:20120127:*:*:*:*:*:* | ||
8.1.0CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:8.1.0:rc0:*:*:*:*:*:* | ||
7.0.0CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:7.0.0:20091005:*:*:*:*:*:* | ||
7.0.0CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:7.0.0:maintenance_0:*:*:*:*:*:* | ||
7.0.0CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:7.0.0:maintenance_1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.