CVE-2019-10241
MediumAdvisory
Published 23 Apr 2019In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.1
- base score, highest
- EPSS
- 0.096
- 95th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 67
- of 17,781 indexed, latest versions
- Container images
- 58
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Cross-site Scripting in Eclipse Jetty
Carried by container images the latest versions of 67 of 17,781 indexed charts deploy, on 58 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| jetty-servermaven | 7.6.0.v20120127, 8.1.7.v20120910, 8.1.9.v20130131, 8.1.12.v20130726+21 more | 9.2.27.v20190403, 9.3.26.v20190403, 9.4.16.v20190411 | 58 |
- OSV records
- GHSA-7vx9-xjhr-rw6h
Charts affected
67 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| MINTmint | 8.0.2 | 1 of 15See more | 43,341 |
| crowdmoxVerified publisher | 2.4.3 | 1 of 3See more | 5,663 |
| datawolfncsaVerified publisher | 1.1.0 | 1 of 3See more | 4,989 |
| polyglotncsaVerified publisher | 0.1.1 | 1 of 18See more | 55,726 |
| comacopencord | 1.0.0 | 1 of 9See more | 88,546 |
| onos-progranopencord | 1.2.7 | 1 of 2See more | 38,865 |
| jmxproxypndaproject | 0.1.0 | 1 of 1See more | 4,177 |
| hive-metastorepresto-loadbalancer | 0.2.3 | 1 of 1See more | 9,606 |
| prometheus-cloudwatch-exporterprometheus-worawutchan | 0.12.0 | 1 of 1See more | 2,831 |
| archivaslamdev | 0.0.7 | 1 of 2See more | 6,907 |
| atlassian-jirasomeblackmagic | 3.3.2 | 1 of 1See more | 13,079 |
| newrelic-private-minionsstarcher | 0.1.2 | 1 of 1See more | 3,164 |
| trinostatcan | 1.23.4 | 1 of 2See more | 13,767 |
| streamastreama | 1.0.1 | 1 of 2See more | 8,554 |
| ubooquityvhdirkVerified publisher | 0.1.3 | 1 of 1See more | 4,303 |
| queryservicewbstack | 0.2.1 | 1 of 1See more | 4,649 |
| is-pattern-1wso2is-pattern1 | 5.11.0 | 1 of 2See more | 6,213 |
Container images carrying it
58 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| slamdev/ | b4b029c9b15f | jetty-server | 9.2.27.v20190403 | 1 |
| snappydatainc/ | fd4b2070466f | jetty-server | 9.3.26.v20190403 | 1 |
| sslhep/ | 9e80af083079 | jetty-server | 9.3.26.v20190403 | 1 |
| thelastpickle/ | 9c53996c457d | jetty-server | 9.4.16.v20190411 | 1 |
| trinodb/ | ee80ab5eeab2 | jetty-server | 9.3.26.v20190403 | 1 |
| xetusoss/ | 88f25242b9ee | jetty-server | 9.2.27.v20190403 | 1 |
| ghcr.io/ | b83b5b81d4b6 | jetty-server | 9.4.16.v20190411 | 1 |
| quay.io/ | 98c26e1b8f70 | jetty-server | 9.4.16.v20190411 | 1 |