LWN.net Logo

eclipse: cross-site scripting

Package(s):eclipse CVE #(s):CVE-2010-4647
Created:December 27, 2010 Updated:May 19, 2011
Description: From the Red Hat bugzilla:

It was reported that the Eclipse Help Contents were vulnerable to Cross Site Scripting vulnerabilities in the /help/index.jsp and /help/advanced/content.jsp URLs that are served by the built-in Jetty Web Server plugin.

Alerts:
Mandriva MDVSA-2011:032 2011-02-20
Red Hat RHSA-2011:0568-01 2011-05-19
Fedora FEDORA-2010-18990 2010-12-17
Fedora FEDORA-2010-19006 2010-12-17

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds