CVE-2024-8184
Lun, 14/10/2024 – 16:15
CVE-2024-8184
CVE-2024-8184
Lun, 14/10/2024 – 16:15
CVE-2024-8184
CVE-2024-6763
Lun, 14/10/2024 – 16:15
CVE-2024-6763
The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI
differs from the common browsers in how it handles a URI that would be
considered invalid if fully validated against the RRC. Specifically HttpURI
and the browser may differ on the value of the host extracted from an
invalid URI and thus a combination of Jetty and a vulnerable browser may
be vulnerable to a open redirect attack or to a SSRF attack if the URI
is used after passing validation checks.
CVE-2024-38863
Lun, 14/10/2024 – 08:15
CVE-2024-38863
CVE-2024-38862
Lun, 14/10/2024 – 08:15
CVE-2024-38862
CVE-2024-9139
Lun, 14/10/2024 – 09:15
CVE-2024-9139
CVE-2024-9137
Lun, 14/10/2024 – 09:15
CVE-2024-9137
CVE-2024-46911
Lun, 14/10/2024 – 09:15
CVE-2024-46911
Roller users who run multi-blog/user Roller websites are recommended to upgrade to version 6.1.4, which fixes the issue.
Roller 6.1.4 release announcement: https://lists.apache.org/thread/3c3f6rwqptyw6wdc95654fq5vlosqdpw
CVE-2024-43701
Lun, 14/10/2024 – 09:15
CVE-2024-43701
CVE-2024-9922
Lun, 14/10/2024 – 03:15
CVE-2024-9922
CVE-2024-9921
Lun, 14/10/2024 – 03:15
CVE-2024-9921