VYPR
Medium severity6.1NVD Advisory· Published Nov 25, 2019· Updated Jun 17, 2026

CVE-2019-17632

CVE-2019-17632

Description

In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.eclipse.jetty:jetty-serverMaven
>= 9.4.21.v20190926, < 9.4.24.v201911209.4.24.v20191120
org.eclipse.jetty:jetty-serverMaven
>= 9.4.22.v20191022, < 9.4.24.v201911209.4.24.v20191120
org.eclipse.jetty:jetty-serverMaven
>= 9.4.23.v20191118, < 9.4.24.v201911209.4.24.v20191120

Affected products

5
  • ghsa-coords
    Range: >= 9.4.21.v20190926, < 9.4.24.v20191120
  • Eclipse/Jettycpe-rescue4 versions
    9.4.21.v20190926+ 3 more
    • (no CPE)range: 9.4.21.v20190926
    • cpe:2.3:a:eclipse:jetty:9.4.22:20191022:*:*:*:*:*:*
    • cpe:2.3:a:eclipse:jetty:9.4.21:20190926:*:*:*:*:*:*
    • cpe:2.3:a:eclipse:jetty:9.4.23:20191118:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.