BR-demo-org / netflix_conductor_fork

Conductor is a microservices orchestration engine - https://netflix.github.io/conductor/
Apache License 2.0
0 stars 0 forks source link

CVE-2019-10241 (Medium) detected in multiple libraries - autoclosed #132

Closed mend-for-github-com[bot] closed 2 years ago

mend-for-github-com[bot] commented 3 years ago

CVE-2019-10241 - Medium Severity Vulnerability

Vulnerable Libraries - jetty-server-8.1.8.v20121106.jar, jetty-server-9.2.10.v20150310.jar, jetty-util-8.1.8.v20121106.jar, jetty-servlet-9.2.10.v20150310.jar, jetty-util-9.2.10.v20150310.jar, jetty-servlet-7.6.16.v20140903.jar, jetty-servlet-8.1.8.v20121106.jar, jetty-util-7.6.16.v20140903.jar, jetty-server-7.6.16.v20140903.jar

jetty-server-8.1.8.v20121106.jar

The core jetty server artifact.

Library home page: http://www.eclipse.org/jetty

Path to dependency file: /server/build.gradle

Path to vulnerable library: /tmp/ws-ua_20210708151457_ISTDYJ/downloadResource_GJPGFO/20210708154145/jetty-server-8.1.8.v20121106.jar

Dependency Hierarchy: - gretty-runner-jetty8-1.2.4.jar (Root Library) - :x: **jetty-server-8.1.8.v20121106.jar** (Vulnerable Library)

jetty-server-9.2.10.v20150310.jar

The core jetty server artifact.

Library home page: http://www.eclipse.org/jetty

Path to dependency file: /server/build.gradle

Path to vulnerable library: /tmp/ws-ua_20210708151457_ISTDYJ/downloadResource_GJPGFO/20210708154148/jetty-server-9.2.10.v20150310.jar

Dependency Hierarchy: - gretty-runner-jetty9-1.2.4.jar (Root Library) - :x: **jetty-server-9.2.10.v20150310.jar** (Vulnerable Library)

jetty-util-8.1.8.v20121106.jar

Utility classes for Jetty

Library home page: http://www.eclipse.org/jetty

Path to dependency file: /server/build.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/8.1.8.v20121106/3174e8d53033e3c4d350eba3112efdc170b40dc/jetty-util-8.1.8.v20121106.jar

Dependency Hierarchy: - gretty-runner-jetty8-1.2.4.jar (Root Library) - jetty-annotations-8.1.8.v20121106.jar - jetty-plus-8.1.8.v20121106.jar - jetty-webapp-8.1.8.v20121106.jar - jetty-xml-8.1.8.v20121106.jar - :x: **jetty-util-8.1.8.v20121106.jar** (Vulnerable Library)

jetty-servlet-9.2.10.v20150310.jar

Jetty Servlet Container

Library home page: http://www.eclipse.org/jetty

Path to dependency file: /server/build.gradle

Path to vulnerable library: /tmp/ws-ua_20210708151457_ISTDYJ/downloadResource_GJPGFO/20210708154147/jetty-servlet-9.2.10.v20150310.jar

Dependency Hierarchy: - gretty-runner-jetty9-1.2.4.jar (Root Library) - :x: **jetty-servlet-9.2.10.v20150310.jar** (Vulnerable Library)

jetty-util-9.2.10.v20150310.jar

Utility classes for Jetty

Library home page: http://www.eclipse.org/jetty

Path to dependency file: /server/build.gradle

Path to vulnerable library: /tmp/ws-ua_20210708151457_ISTDYJ/downloadResource_GJPGFO/20210708154148/jetty-util-9.2.10.v20150310.jar

Dependency Hierarchy: - gretty-runner-jetty9-1.2.4.jar (Root Library) - javax-websocket-server-impl-9.2.10.v20150310.jar - javax-websocket-client-impl-9.2.10.v20150310.jar - websocket-client-9.2.10.v20150310.jar - :x: **jetty-util-9.2.10.v20150310.jar** (Vulnerable Library)

jetty-servlet-7.6.16.v20140903.jar

Jetty Servlet Container

Library home page: http://www.eclipse.org/jetty

Path to dependency file: /server/build.gradle

Path to vulnerable library: /tmp/ws-ua_20210708151457_ISTDYJ/downloadResource_GJPGFO/20210708154143/jetty-servlet-7.6.16.v20140903.jar

Dependency Hierarchy: - gretty-runner-jetty7-1.2.4.jar (Root Library) - :x: **jetty-servlet-7.6.16.v20140903.jar** (Vulnerable Library)

jetty-servlet-8.1.8.v20121106.jar

Jetty Servlet Container

Library home page: http://www.eclipse.org/jetty

Path to dependency file: /server/build.gradle

Path to vulnerable library: /tmp/ws-ua_20210708151457_ISTDYJ/downloadResource_GJPGFO/20210708154145/jetty-servlet-8.1.8.v20121106.jar

Dependency Hierarchy: - gretty-runner-jetty8-1.2.4.jar (Root Library) - :x: **jetty-servlet-8.1.8.v20121106.jar** (Vulnerable Library)

jetty-util-7.6.16.v20140903.jar

Utility classes for Jetty

Library home page: http://www.eclipse.org/jetty

Path to dependency file: /server/build.gradle

Path to vulnerable library: /tmp/ws-ua_20210708151457_ISTDYJ/downloadResource_GJPGFO/20210708154143/jetty-util-7.6.16.v20140903.jar

Dependency Hierarchy: - gretty-runner-jetty7-1.2.4.jar (Root Library) - jetty-webapp-7.6.16.v20140903.jar - jetty-xml-7.6.16.v20140903.jar - :x: **jetty-util-7.6.16.v20140903.jar** (Vulnerable Library)

jetty-server-7.6.16.v20140903.jar

The core jetty server artifact.

Library home page: http://www.eclipse.org/jetty

Path to dependency file: /server/build.gradle

Path to vulnerable library: /tmp/ws-ua_20210708151457_ISTDYJ/downloadResource_GJPGFO/20210708154142/jetty-server-7.6.16.v20140903.jar

Dependency Hierarchy: - gretty-runner-jetty7-1.2.4.jar (Root Library) - :x: **jetty-server-7.6.16.v20140903.jar** (Vulnerable Library)

Found in HEAD commit: 975ea99358eaa6f34b7c8c0c0dce2a0a92a39da5

Found in base branch: master

Vulnerability Details

In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.

Publish Date: 2019-04-22

URL: CVE-2019-10241

CVSS 3 Score Details (6.1)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Changed - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10241

Release Date: 2019-04-22

Fix Resolution (org.eclipse.jetty:jetty-server): 9.2.27.v20190403

Direct dependency fix Resolution (org.akhikhl.gretty:gretty-runner-jetty9): 2.0.0

Fix Resolution (org.eclipse.jetty:jetty-servlet): 9.2.27.v20190403

Direct dependency fix Resolution (org.akhikhl.gretty:gretty-runner-jetty9): 2.0.0

Fix Resolution (org.eclipse.jetty:jetty-util): 9.2.27.v20190403

Direct dependency fix Resolution (org.akhikhl.gretty:gretty-runner-jetty9): 2.0.0


:rescue_worker_helmet: Automatic Remediation is available for this issue

mend-bolt-for-github[bot] commented 2 years ago

:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.