{"id":"GHSA-5mq8-h82p-wjf2","summary":"Jetty Javascript Inclusion Vulnerability","details":"Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (`%0a`).","aliases":["CVE-2002-1533"],"modified":"2024-11-28T05:41:39.980409Z","published":"2022-04-30T18:21:21Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-02-12T20:43:18Z","nvd_published_at":"2003-03-31T05:00:00Z","cwe_ids":["CWE-80"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2002-1533"},{"type":"WEB","url":"https://web.archive.org/web/20040705203137/http://xforce.iss.net/xforce/xfdb/10219"},{"type":"WEB","url":"https://web.archive.org/web/20041213153950/http://archives.neohapsis.com/archives/bugtraq/2002-09/0337.html"},{"type":"WEB","url":"https://web.archive.org/web/20061020173202/http://www.securityfocus.com/bid/5821"}],"affected":[{"package":{"name":"org.mortbay.jetty:jetty","ecosystem":"Maven","purl":"pkg:maven/org.mortbay.jetty/jetty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.1"}]}],"versions":["4.1-rc1","4.1-rc6","test-6.0.0","test-6.0.0rc3","test-6.0.0rc4","test-6.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-5mq8-h82p-wjf2/GHSA-5mq8-h82p-wjf2.json"}}],"schema_version":"1.9.0"}