GHSA-xc67-hjx6-cgg6 · Severity: medium · Ecosystem: maven — Installation information leak in Eclipse Jetty
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on jetty-distribution and jetty-home will include at the end of the Handler tree a DefaultHandler, which is responsible for reporting this 404 error, it presents the various configured contexts as HTML for users to click through to. This produced HTML includes output that contains the configured fully qualified directory base resource location for each context.
Conclusion & alert: CVE-2019-10247 is rated Moderate Risk (52.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 3.36%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-04 | 3.10% | 3.36% | +0.26% |
| 2 | 2026-04-22 | 4.16% | 3.10% | -1.05% |
| 3 | 2026-04-13 | — | 4.16% | — |
Full EPSS history (58 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-xc67-hjx6-cgg6 · Severity: medium · Ecosystem: maven — Installation information leak in Eclipse Jetty
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2019-10247 not yet assigned priority: Debian including 1 source packages (jetty9), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2019-10247 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2019-10247 |
ubuntu
|
medium | CVE-2019-10247 medium priority: Ubuntu including 3 source packages (jetty, jetty8, jetty9), 57 status rows across 19 suites (bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 33, ignored 11, needed 10, needs-triage 2, released 1. | https://ubuntu.com/security/CVE-2019-10247 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| eclipse | jetty | 7.0.0 | cpe:2.3:a:eclipse:jetty:7.0.0:20091005:*:*:*:*:*:* |
| eclipse | jetty | 7.0.0 | cpe:2.3:a:eclipse:jetty:7.0.0:maintenance_0:*:*:*:*:*:* |
| eclipse | jetty | 7.0.0 | cpe:2.3:a:eclipse:jetty:7.0.0:maintenance_1:*:*:*:*:*:* |
| eclipse | jetty | 7.0.0 | cpe:2.3:a:eclipse:jetty:7.0.0:maintenance_2:*:*:*:*:*:* |
| eclipse | jetty | 7.0.0 | cpe:2.3:a:eclipse:jetty:7.0.0:maintenance_3:*:*:*:*:*:* |
| eclipse | jetty | 7.0.0 | cpe:2.3:a:eclipse:jetty:7.0.0:maintenance_4:*:*:*:*:*:* |
| eclipse | jetty | 7.0.0 | cpe:2.3:a:eclipse:jetty:7.0.0:rc0:*:*:*:*:*:* |
| eclipse | jetty | 7.0.0 | cpe:2.3:a:eclipse:jetty:7.0.0:rc1:*:*:*:*:*:* |
| eclipse | jetty | 7.0.0 | cpe:2.3:a:eclipse:jetty:7.0.0:rc3:*:*:*:*:*:* |
| eclipse | jetty | 7.0.0 | cpe:2.3:a:eclipse:jetty:7.0.0:rc4:*:*:*:*:*:* |
| eclipse | jetty | 7.0.0 | cpe:2.3:a:eclipse:jetty:7.0.0:rc5:*:*:*:*:*:* |
| eclipse | jetty | 7.0.0 | cpe:2.3:a:eclipse:jetty:7.0.0:rc6:*:*:*:*:*:* |
| eclipse | jetty | 7.0.1 | cpe:2.3:a:eclipse:jetty:7.0.1:20091125:*:*:*:*:*:* |
| eclipse | jetty | 7.0.2 | cpe:2.3:a:eclipse:jetty:7.0.2:20100331:*:*:*:*:*:* |
| eclipse | jetty | 7.0.2 | cpe:2.3:a:eclipse:jetty:7.0.2:rc0:*:*:*:*:*:* |
| eclipse | jetty | 7.1.0 | cpe:2.3:a:eclipse:jetty:7.1.0:20100505:*:*:*:*:*:* |
| eclipse | jetty | 7.1.0 | cpe:2.3:a:eclipse:jetty:7.1.0:rc0:*:*:*:*:*:* |
| eclipse | jetty | 7.1.0 | cpe:2.3:a:eclipse:jetty:7.1.0:rc1:*:*:*:*:*:* |
| eclipse | jetty | 7.1.1 | cpe:2.3:a:eclipse:jetty:7.1.1:20100517:*:*:*:*:*:* |
| eclipse | jetty | 7.1.2 | cpe:2.3:a:eclipse:jetty:7.1.2:20100523:*:*:*:*:*:* |
| eclipse | jetty | 7.1.3 | cpe:2.3:a:eclipse:jetty:7.1.3:20100526:*:*:*:*:*:* |
| eclipse | jetty | 7.1.4 | cpe:2.3:a:eclipse:jetty:7.1.4:20100610:*:*:*:*:*:* |
| eclipse | jetty | 7.1.5 | cpe:2.3:a:eclipse:jetty:7.1.5:20100705:*:*:*:*:*:* |
| eclipse | jetty | 7.1.6 | cpe:2.3:a:eclipse:jetty:7.1.6:20100715:*:*:*:*:*:* |
| eclipse | jetty | 7.2.0 | cpe:2.3:a:eclipse:jetty:7.2.0:20101020:*:*:*:*:*:* |
| eclipse | jetty | 7.2.0 | cpe:2.3:a:eclipse:jetty:7.2.0:rc0:*:*:*:*:*:* |
| eclipse | jetty | 7.2.1 | cpe:2.3:a:eclipse:jetty:7.2.1:20101111:*:*:*:*:*:* |
| eclipse | jetty | 7.2.2 | cpe:2.3:a:eclipse:jetty:7.2.2:20101205:*:*:*:*:*:* |
| eclipse | jetty | 7.3.0 | cpe:2.3:a:eclipse:jetty:7.3.0:20110203:*:*:*:*:*:* |
| eclipse | jetty | 7.3.1 | cpe:2.3:a:eclipse:jetty:7.3.1:20110307:*:*:*:*:*:* |
| eclipse | jetty | 7.4.0 | cpe:2.3:a:eclipse:jetty:7.4.0:20110414:*:*:*:*:*:* |
| eclipse | jetty | 7.4.0 | cpe:2.3:a:eclipse:jetty:7.4.0:rc0:*:*:*:*:*:* |
| eclipse | jetty | 7.4.1 | cpe:2.3:a:eclipse:jetty:7.4.1:20110513:*:*:*:*:*:* |
| eclipse | jetty | 7.4.2 | cpe:2.3:a:eclipse:jetty:7.4.2:20110526:*:*:*:*:*:* |
| eclipse | jetty | 7.4.3 | cpe:2.3:a:eclipse:jetty:7.4.3:20110630:*:*:*:*:*:* |
| eclipse | jetty | 7.4.3 | cpe:2.3:a:eclipse:jetty:7.4.3:20110701:*:*:*:*:*:* |
| eclipse | jetty | 7.4.4 | cpe:2.3:a:eclipse:jetty:7.4.4:20110707:*:*:*:*:*:* |
| eclipse | jetty | 7.4.5 | cpe:2.3:a:eclipse:jetty:7.4.5:20110725:*:*:*:*:*:* |
| eclipse | jetty | 7.5.0 | cpe:2.3:a:eclipse:jetty:7.5.0:20110901:*:*:*:*:*:* |
| eclipse | jetty | 7.5.0 | cpe:2.3:a:eclipse:jetty:7.5.0:rc0:*:*:*:*:*:* |
| eclipse | jetty | 7.5.0 | cpe:2.3:a:eclipse:jetty:7.5.0:rc1:*:*:*:*:*:* |
| eclipse | jetty | 7.5.0 | cpe:2.3:a:eclipse:jetty:7.5.0:rc2:*:*:*:*:*:* |
| eclipse | jetty | 7.5.1 | cpe:2.3:a:eclipse:jetty:7.5.1:20110908:*:*:*:*:*:* |
| eclipse | jetty | 7.5.2 | cpe:2.3:a:eclipse:jetty:7.5.2:20111006:*:*:*:*:*:* |
| eclipse | jetty | 7.5.3 | cpe:2.3:a:eclipse:jetty:7.5.3:20111011:*:*:*:*:*:* |
| eclipse | jetty | 7.5.4 | cpe:2.3:a:eclipse:jetty:7.5.4:20111024:*:*:*:*:*:* |
| eclipse | jetty | 7.6.0 | cpe:2.3:a:eclipse:jetty:7.6.0:20120125:*:*:*:*:*:* |
| eclipse | jetty | 7.6.0 | cpe:2.3:a:eclipse:jetty:7.6.0:20120127:*:*:*:*:*:* |
| eclipse | jetty | 7.6.0 | cpe:2.3:a:eclipse:jetty:7.6.0:rc0:*:*:*:*:*:* |
| eclipse | jetty | 7.6.0 | cpe:2.3:a:eclipse:jetty:7.6.0:rc1:*:*:*:*:*:* |
| eclipse | jetty | 7.6.0 | cpe:2.3:a:eclipse:jetty:7.6.0:rc2:*:*:*:*:*:* |
| eclipse | jetty | 7.6.0 | cpe:2.3:a:eclipse:jetty:7.6.0:rc3:*:*:*:*:*:* |
| eclipse | jetty | 7.6.0 | cpe:2.3:a:eclipse:jetty:7.6.0:rc4:*:*:*:*:*:* |
| eclipse | jetty | 7.6.0 | cpe:2.3:a:eclipse:jetty:7.6.0:rc5:*:*:*:*:*:* |
| eclipse | jetty | 7.6.1 | cpe:2.3:a:eclipse:jetty:7.6.1:20120215:*:*:*:*:*:* |
| eclipse | jetty | 7.6.2 | cpe:2.3:a:eclipse:jetty:7.6.2:20120302:*:*:*:*:*:* |
| eclipse | jetty | 7.6.2 | cpe:2.3:a:eclipse:jetty:7.6.2:20120308:*:*:*:*:*:* |
| eclipse | jetty | 7.6.3 | cpe:2.3:a:eclipse:jetty:7.6.3:20120413:*:*:*:*:*:* |
| eclipse | jetty | 7.6.3 | cpe:2.3:a:eclipse:jetty:7.6.3:20120416:*:*:*:*:*:* |
| eclipse | jetty | 7.6.4 | cpe:2.3:a:eclipse:jetty:7.6.4:20120522:*:*:*:*:*:* |
| eclipse | jetty | 7.6.4 | cpe:2.3:a:eclipse:jetty:7.6.4:20120524:*:*:*:*:*:* |
| eclipse | jetty | 7.6.5 | cpe:2.3:a:eclipse:jetty:7.6.5:20120713:*:*:*:*:*:* |
| eclipse | jetty | 7.6.5 | cpe:2.3:a:eclipse:jetty:7.6.5:20120716:*:*:*:*:*:* |
| eclipse | jetty | 7.6.6 | cpe:2.3:a:eclipse:jetty:7.6.6:20120903:*:*:*:*:*:* |
| eclipse | jetty | 7.6.7 | cpe:2.3:a:eclipse:jetty:7.6.7:20120910:*:*:*:*:*:* |
| eclipse | jetty | 7.6.8 | cpe:2.3:a:eclipse:jetty:7.6.8:20121106:*:*:*:*:*:* |
| eclipse | jetty | 7.6.9 | cpe:2.3:a:eclipse:jetty:7.6.9:20130131:*:*:*:*:*:* |
| eclipse | jetty | 7.6.10 | cpe:2.3:a:eclipse:jetty:7.6.10:20130312:*:*:*:*:*:* |
| eclipse | jetty | 7.6.11 | cpe:2.3:a:eclipse:jetty:7.6.11:20130520:*:*:*:*:*:* |
| eclipse | jetty | 7.6.11 | cpe:2.3:a:eclipse:jetty:7.6.11:20130725:*:*:*:*:*:* |
| eclipse | jetty | 7.6.12 | cpe:2.3:a:eclipse:jetty:7.6.12:20130726:*:*:*:*:*:* |
| eclipse | jetty | 7.6.13 | cpe:2.3:a:eclipse:jetty:7.6.13:20130910:*:*:*:*:*:* |
| eclipse | jetty | 7.6.13 | cpe:2.3:a:eclipse:jetty:7.6.13:20130916:*:*:*:*:*:* |
| eclipse | jetty | 7.6.14 | cpe:2.3:a:eclipse:jetty:7.6.14:20131031:*:*:*:*:*:* |
| eclipse | jetty | 7.6.15 | cpe:2.3:a:eclipse:jetty:7.6.15:20140411:*:*:*:*:*:* |
| eclipse | jetty | 7.6.16 | cpe:2.3:a:eclipse:jetty:7.6.16:20140903:*:*:*:*:*:* |
| eclipse | jetty | 7.6.17 | cpe:2.3:a:eclipse:jetty:7.6.17:20150415:*:*:*:*:*:* |
| eclipse | jetty | 7.6.18 | cpe:2.3:a:eclipse:jetty:7.6.18:20150929:*:*:*:*:*:* |
| eclipse | jetty | 7.6.19 | cpe:2.3:a:eclipse:jetty:7.6.19:20160209:*:*:*:*:*:* |
| eclipse | jetty | 7.6.20 | cpe:2.3:a:eclipse:jetty:7.6.20:20160902:*:*:*:*:*:* |