Mortbay maintains Jetty, a lightweight Java-based HTTP server and servlet container widely embedded in enterprise applications and microservices architectures. The recurring vulnerability classes—cross-site scripting, information disclosure, input validation, and path traversal—reflect the web-request handling and input-parsing complexity inherent to HTTP middleware, and public exploit code frequently becomes available for identified flaws in this category. Defenders should treat Jetty updates as routine and priority, particularly in internet-reachable deployments; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mortbay over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1523MEDIUM Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via dir | May 5, 2009 | 5.0 | 41 | NO | YES |
CVE-2005-3747MEDIUM Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash (" | Nov 22, 2005 | 5.0 | 25 | NO | YES |
CVE-2009-4612MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTM | Jan 13, 2010 | 4.3 | 24 | NO | YES |
CVE-2009-4610MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to jsp/du | Jan 13, 2010 | 4.3 | 23 | NO | YES |
CVE-2009-5049MEDIUM WebApp JSP Snoop page XSS in jetty though 6.1.21. | Nov 6, 2019 | 6.1 | 22 | NO | NO |
CVE-2009-5048MEDIUM Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20. | Nov 6, 2019 | 6.1 | 22 | NO | NO |
CVE-2011-4461MEDIUM Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause | Dec 30, 2011 | 5.3 | 22 | NO | NO |
CVE-2009-4611HIGH Mort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace data without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or pos | Jan 13, 2010 | 7.5 | 20 | NO | NO |
CVE-2009-4609MEDIUM The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other data via a request to a URI ending in /d | Jan 13, 2010 | 5.0 | 19 | NO | NO |
CVE-2009-1524MEDIUM Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a | May 5, 2009 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mortbay.
Media articles that mention a CVE ID that affects a product developed by Mortbay — matched by CVE ID, not by vendor name.