jetty: error path information disclosure
Published Apr 22, 2019
5.3
MEDIUMCVSS 3.1
EPSS 5.94%
Description
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on jetty-distribution and jetty-home will include at the end of the Handler tree a DefaultHandler, which is responsible for reporting this 404 error, it presents the various configured contexts as HTML for users to click through to. This produced HTML includes output that contains the configured fully qualified directory base resource location for each context.
Affected products
-
- Version 7.xStatusaffectedConstraints-
- Version 8.xStatusaffectedConstraints-
- Version unspecifiedStatusaffectedConstraints<=9.2.27
- Version unspecifiedStatusaffectedConstraints<=9.3.26
- Version unspecifiedStatusaffectedConstraints<=9.4.16
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| The Eclipse Foundation | Eclipse Jetty | n/a |
|
Configuration 1
- 7.0.0
- 7.0.0
- 7.0.0
- 7.0.0
- 7.0.0
- 7.0.0
- 7.0.0
- 7.0.0
- 7.0.0
- 7.0.0
- 7.0.0
- 7.0.0
- 7.0.1
- 7.0.2
- 7.0.2
- 7.1.0
- 7.1.0
- 7.1.0
- 7.1.1
- 7.1.2
- 7.1.3
- 7.1.4
- 7.1.5
- 7.1.6
- 7.2.0
- 7.2.0
- 7.2.1
- 7.2.2
- 7.3.0
- 7.3.1
- 7.4.0
- 7.4.0
- 7.4.1
- 7.4.2
- 7.4.3
- 7.4.3
- 7.4.4
- 7.4.5
- 7.5.0
- 7.5.0
- 7.5.0
- 7.5.0
- 7.5.1
- 7.5.2
- 7.5.3
- 7.5.4
- 7.6.0
- 7.6.0
- 7.6.0
- 7.6.0
- 7.6.0
- 7.6.0
- 7.6.0
- 7.6.0
- 7.6.1
- 7.6.2
- 7.6.2
- 7.6.3
- 7.6.3
- 7.6.4
- 7.6.4
- 7.6.5
- 7.6.5
- 7.6.6
- 7.6.7
- 7.6.8
- 7.6.9
- 7.6.10
- 7.6.11
- 7.6.11
- 7.6.12
- 7.6.13
- 7.6.13
- 7.6.14
- 7.6.15
- 7.6.16
- 7.6.17
- 7.6.18
- 7.6.19
- 7.6.20
- 7.6.21
- 8.0.0
- 8.0.0
- 8.0.0
- 8.0.0
- 8.0.0
- 8.0.0
- 8.0.1
- 8.0.2
- 8.0.3
- 8.0.4
- 8.1.0
- 8.1.0
- 8.1.0
- 8.1.0
- 8.1.0
- 8.1.0
- 8.1.1
- 8.1.2
- 8.1.2
- 8.1.3
- 8.1.4
- 8.1.5
- 8.1.5
- 8.1.6
- 8.1.7
- 8.1.8
- 8.1.9
- 8.1.10
- 8.1.11
- 8.1.12
- 8.1.12
- 8.1.13
- 8.1.13
- 8.1.14
- 8.1.15
- 8.1.16
- 8.1.17
- 8.1.18
- 8.1.19
- 8.1.20
- 8.1.21
- 8.1.22
- 8.2.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.1
- 9.0.2
- 9.0.2
- 9.0.3
- 9.0.4
- 9.0.4
- 9.0.5
- 9.0.5
- 9.0.6
- 9.0.6
- 9.0.7
- 9.0.7
- 9.1.0
- 9.1.0
- 9.1.0
- 9.1.0
- 9.1.0
- 9.1.1
- 9.1.2
- 9.1.3
- 9.1.4
- 9.1.5
- 9.1.6
- 9.1.6
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.1
- 9.2.2
- 9.2.3
- 9.2.4
- 9.2.5
- 9.2.6
- 9.2.6
- 9.2.7
- 9.2.8
- 9.2.9
- 9.2.10
- 9.2.11
- 9.2.11
- 9.2.11
- 9.2.12
- 9.2.12
- 9.2.13
- 9.2.14
- 9.2.15
- 9.2.16
- 9.2.16
- 9.2.17
- 9.2.18
- 9.2.19
- 9.2.20
- 9.2.21
- 9.2.22
- 9.2.23
- 9.2.24
- 9.2.25
- 9.2.26
- 9.2.27
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.1
- 9.3.2
- 9.3.3
- 9.3.3
- 9.3.4
- 9.3.4
- 9.3.4
- 9.3.4
- 9.3.5
- 9.3.6
- 9.3.7
- 9.3.7
- 9.3.7
- 9.3.8
- 9.3.8
- 9.3.8
- 9.3.9
- 9.3.9
- 9.3.9
- 9.3.10
- 9.3.10
- 9.3.11
- 9.3.11
- 9.3.12
- 9.3.13
- 9.3.13
- 9.3.14
- 9.3.15
- 9.3.16
- 9.3.16
- 9.3.17
- 9.3.17
- 9.3.18
- 9.3.19
- 9.3.20
- 9.3.21
- 9.3.21
- 9.3.21
- 9.3.22
- 9.3.23
- 9.3.24
- 9.3.25
- 9.3.26
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.1
- 9.4.1
- 9.4.2
- 9.4.2
- 9.4.3
- 9.4.3
- 9.4.4
- 9.4.4
- 9.4.4
- 9.4.5
- 9.4.5
- 9.4.6
- 9.4.6
- 9.4.7
- 9.4.7
- 9.4.7
- 9.4.8
- 9.4.8
- 9.4.9
- 9.4.10
- 9.4.10
- 9.4.10
- 9.4.11
- 9.4.12
- 9.4.12
- 9.4.12
- 9.4.12
- 9.4.13
- 9.4.14
- 9.4.15
Configuration 2
- ≥ 3.0 · ≤ 3.1.3
- n/a
- n/a
- n/a
- n/a
- ≥ 9.6
- n/a
- ≥ 9.6
- ≥ 9.6
- n/a
Configuration 3
- 21.0.2
- 12.1.1
- 8.0.0
- 8.1.0
- 8.1.1
- 8.2.0
- 6.0
- 6.1
- 7.0
- 8.0.0
- 8.1.0
- 8.1.1
- 8.2.0
- 8.0.0
- 8.1.0
- 8.1.1
- 8.2.0
- 12.2.1.3.0
- 12.2.1.4.0
- 3.2.0
- 13.2
- 13.3
- ≥ 11.5.0 · ≤ 11.7.0
- 5.2.0
- 12.0.0
- 12.1.0
- 12.2.1.3.0
- 12.2.1.4.0
- 4.2.0
- 4.2.1
- 7.1
- 15.0
- 16.0
- 17.0
- 12.2.1.3.0
- 12.2.1.4.0
Configuration 4
- 9.0
- 10.0
No data.
Red Hat AMQ
jetty
Fixed · RHSA-2020:0922
Red Hat AMQ 7.4.3
jetty
Fixed · RHSA-2020:1445
Red Hat Fuse 7.6.0
n/a
Fixed · RHSA-2020:0983
Red Hat Enterprise Linux 6
jetty-eclipse
Out of support scope
Red Hat Enterprise Linux 7
jetty
Will not fix
Red Hat Fuse 7
jetty
Affected
Red Hat JBoss A-MQ 6
jetty
Out of support scope
Red Hat JBoss Fuse 6
jetty
Out of support scope
Red Hat Satellite 5
nutch
Out of support scope
Red Hat Software Collections
rh-java-common-jetty
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AMQ | jetty | Fixed | RHSA-2020:0922 |
| Red Hat AMQ 7.4.3 | jetty | Fixed | RHSA-2020:1445 |
| Red Hat Fuse 7.6.0 | n/a | Fixed | RHSA-2020:0983 |
| Red Hat Enterprise Linux 6 | jetty-eclipse | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | jetty | Will not fix | n/a |
| Red Hat Fuse 7 | jetty | Affected | n/a |
| Red Hat JBoss A-MQ 6 | jetty | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | jetty | Out of support scope | n/a |
| Red Hat Satellite 5 | nutch | Out of support scope | n/a |
| Red Hat Software Collections | rh-java-common-jetty | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of jetty which is embedded in the nutch package as shipped with Red Hat Satellite 5. The jetty server is not exposed, as such exploitation is difficult, Red Hat Product Security has rated this issue as having security impact of Low in the context of Red Hat Satellite 5. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
AV:N/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (54 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.94% (0.05941) | 93.04th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.78% (0.05782) | 92.09th | v5 (v2026.06.15) |
| Apr 22, 2026 | 3.10% (0.03104) | 86.84th | v4 (v2025.03.14) |
| Apr 13, 2026 | 4.16% (0.04156) | 88.68th | v4 (v2025.03.14) |
| Mar 4, 2026 | 6.48% (0.06477) | 90.90th | v4 (v2025.03.14) |
| Mar 1, 2026 | 2.22% (0.02220) | 84.27th | v4 (v2025.03.14) |
| Feb 4, 2026 | 6.59% (0.06593) | 90.94th | v4 (v2025.03.14) |
| Feb 1, 2026 | 2.26% (0.02262) | 84.32th | v4 (v2025.03.14) |
| Jan 4, 2026 | 6.59% (0.06593) | 90.87th | v4 (v2025.03.14) |
| Jan 1, 2026 | 2.26% (0.02262) | 84.26th | v4 (v2025.03.14) |
| Dec 28, 2025 | 6.59% (0.06593) | 90.84th | v4 (v2025.03.14) |
| Dec 27, 2025 | 5.57% (0.05572) | 90.05th | v4 (v2025.03.14) |
| Dec 4, 2025 | 6.59% (0.06593) | 90.80th | v4 (v2025.03.14) |
| Dec 1, 2025 | 2.26% (0.02262) | 84.17th | v4 (v2025.03.14) |
| Nov 21, 2025 | 6.59% (0.06593) | 90.77th | v4 (v2025.03.14) |
| Nov 18, 2025 | 5.02% (0.05021) | 88.68th | v4 (v2025.03.14) |
| Nov 4, 2025 | 6.59% (0.06593) | 90.74th | v4 (v2025.03.14) |
| Nov 1, 2025 | 2.26% (0.02262) | 84.11th | v4 (v2025.03.14) |
| Oct 28, 2025 | 6.59% (0.06593) | 90.74th | v4 (v2025.03.14) |
| Oct 27, 2025 | 5.57% (0.05572) | 89.88th | v4 (v2025.03.14) |
| Oct 4, 2025 | 6.59% (0.06593) | 90.79th | v4 (v2025.03.14) |
| Oct 1, 2025 | 2.26% (0.02262) | 84.09th | v4 (v2025.03.14) |
| Sep 4, 2025 | 5.57% (0.05572) | 89.94th | v4 (v2025.03.14) |
| Sep 1, 2025 | 2.08% (0.02075) | 83.35th | v4 (v2025.03.14) |
| Aug 4, 2025 | 6.02% (0.06016) | 90.35th | v4 (v2025.03.14) |
| Aug 1, 2025 | 2.25% (0.02249) | 84.01th | v4 (v2025.03.14) |
| Jul 30, 2025 | 6.02% (0.06016) | 90.34th | v4 (v2025.03.14) |
| Jul 4, 2025 | 7.11% (0.07110) | 91.09th | v4 (v2025.03.14) |
| Jul 1, 2025 | 2.45% (0.02451) | 84.58th | v4 (v2025.03.14) |
| Jun 4, 2025 | 6.18% (0.06181) | 90.35th | v4 (v2025.03.14) |
| Jun 1, 2025 | 2.11% (0.02112) | 83.31th | v4 (v2025.03.14) |
| May 4, 2025 | 6.18% (0.06181) | 90.31th | v4 (v2025.03.14) |
| May 1, 2025 | 2.11% (0.02112) | 83.21th | v4 (v2025.03.14) |
| Mar 30, 2025 | 6.59% (0.06593) | 90.25th | v4 (v2025.03.14) |
| Mar 29, 2025 | 45.80% (0.45802) | 96.49th | v4 (v2025.03.14) |
| Mar 24, 2025 | 6.59% (0.06593) | 90.25th | v4 (v2025.03.14) |
| Mar 23, 2025 | 32.63% (0.32635) | 96.35th | v4 (v2025.03.14) |
| Mar 17, 2025 | 6.59% (0.06593) | 90.48th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.56% (0.00563) | 78.48th | v3 (v2023.03.01) |
| Apr 15, 2024 | 0.69% (0.00695) | 79.92th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.36% (0.00359) | 71.39th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.36% (0.00359) | 69.03th | v3 (v2023.03.01) |
| Mar 13, 2023 | 0.25% (0.00249) | 60.98th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.29% (0.00290) | 64.10th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 23.44% (0.23437) | 94.77th | v2 (v2022.01.01) |
| Feb 3, 2022 | 14.63% (0.14629) | 89.77th | v1 |
| Jan 6, 2022 | 14.63% (0.14629) | 89.65th | v1 |
| Sep 1, 2021 | 3.68% (0.03679) | 82.80th | v1 |
| Aug 6, 2021 | 3.68% (0.03679) | 0.00th | v1 |
| Jun 15, 2021 | 3.48% (0.03480) | 0.00th | v1 |
| May 15, 2021 | 3.28% (0.03281) | 0.00th | v1 |
| Apr 14, 2021 | 3.08% (0.03080) | 0.00th | v1 |
References (29)
- https://access.redhat.com/security/cve/CVE-2019-10247 Vendor Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=546577 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1705993 Issue Tracking
- https://github.com/advisories/GHSA-xc67-hjx6-cgg6 Advisory
- https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/ac51944aef91dd5006b8510b0bef337adaccfe962fb90e7af9c22db4%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/ac51944aef91dd5006b8510b0bef337adaccfe962fb90e7af9c22db4@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E
- https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/05/msg00016.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10247
- https://security.netapp.com/advisory/ntap-20190509-0003/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-10247
- https://www.debian.org/security/2021/dsa-4949 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.