MEDIUMMaven

Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations

Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations

Published 3 years agoUpdated 5 days agoSource: OSV

Affected packages

  • org.eclipse.jetty:jetty-xml10.0.0-alpha0 → 10.0.16

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.