SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#237888

Mortbay Jetty Dump Servlet vulnerable to cross-site scripting

Overview

The Mortbay Jetty Dump Servlet contains a cross-site scripting vulnerability.

I. Description

Mortbay Jetty is a web server that is written in Java. The Dump Servlet that is included with Jetty is vulnerable to cross-site scripting. Note that according to the vendor, the Dump Servlet is for testing purposes and is not intended to be included in a live web site.

II. Impact

A remote, unauthenticated attacker may be able to perform a cross-site scripting attack against a Jetty web server. More information about cross-site scripting can be found in CERT Advisory CA-2000-02.

III. Solution

Apply an update

This issue is addressed in Mortbay Jetty 6.1.6. Details are available in the release notes.

Remove the Dump Servlet

This issue can be mitigated by removing the Dump Servlet from the web server.

Systems Affected

VendorStatusDate NotifiedDate Updated
Mort BayVulnerable4-Dec-2007

References


http://svn.codehaus.org/jetty/jetty/trunk/VERSION.txt
http://jira.codehaus.org/browse/JETTY-452
http://dist.codehaus.org/jetty/jetty-6.1.6/

Credit

Thanks to Tomasz Kuczynski for reporting this vulnerability.

This document was written by Will Dormann.

Other Information

Date Public:2007-11-05
Date First Published:2007-12-04
Date Last Updated:2007-12-03
CERT Advisory: 
CVE-ID(s):CVE-2007-5613
NVD-ID(s):CVE-2007-5613
US-CERT Technical Alerts: 
Metric:3.29
Document Revision:7

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader