{"id":"CVE-2019-17632","aliases":["GHSA-5h9j-q6j2-253f"],"url":"https://o3.security/vulnerability/CVE-2019-17632","summary":"Unescaped exception messages in error responses in Jetty","details":"In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.","published":"2019-11-25T22:15:11.437Z","modified":"2026-08-27T08:15:19.119741Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"org.eclipse.jetty:jetty-server","fixedVersion":"9.4.24.v20191120"},{"ecosystem":"Maven","name":"org.eclipse.jetty:jetty-server","fixedVersion":"9.4.24.v20191120"},{"ecosystem":"Maven","name":"org.eclipse.jetty:jetty-server","fixedVersion":"9.4.24.v20191120"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SAITZ27GKPD2CCNHGT2VBT4VWIBUJJNS/"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"REPORT","url":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=553443"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T08:15:19.119741Z"}}