CVE-2019-10241: Apache ActiveMQ
Medium severity, CVSS 6.1. EPSS: 9.4% chance of exploitation in the next 30 days.
In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.
Affected products
- Apache ActiveMQ: version 5.15.9 only
- Apache Drill: version 1.16.0 only
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Eclipse Jetty: version 9.2.0 only; version 9.2.1 only; version 9.2.2 only; version 9.2.3 only; version 9.2.4 only; version 9.2.5 only; …
- Oracle Flexcube Core Banking: from 11.5.0, up to and including 11.7.0; version 5.2.0 only
- Oracle Rest Data Services: version 11.2.0.4 only; version 12.1.0.2 only; version 12.2.0.1 only; version 18c only
- Oracle Retail Xstore Point Of Service: version 7.1 only; version 15.0 only; version 16.0 only; version 17.0 only
Published 2019-04-22. Last modified 2026-06-17.