maven package report

Is org.eclipse.jetty:jetty-webapp safe?

3 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
4.4%

chance of exploitation in the next 30 days

xyz score
3.5

CyberXYZ composite, out of 10

fig. 01 — GHSA-g3wg-6mcf-8jj6, the advisory selected below

// advisories

GHSA-g3wg-6mcf-8jj6

HIGHCVE-2020-27216

On Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. If the attacker wins the race then they will have read and write permission to the subdirectory used to unpack web appli

Affected
>= 10.0.0.beta1, <= 10.0.0.beta2, >= 11.0.0.beta1, <= 11.0.0.beta2, < 9.4.33.v20201020
Fixed in
10.0.0.beta3
Weakness
CWE-378
Published
2020-11-04
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 01:48 UTC. The most recent advisory here was published 2021-07-19. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.eclipse.jetty:jetty-webapp safe? maven package security report | CyberXYZ