Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-4800

Опубликовано: 13 апр. 2017
Источник: debian
EPSS Низкий

Описание

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jetty9not-affectedpackage
jetty8not-affectedpackage
jettynot-affectedpackage

Примечания

  • http://www.ocert.org/advisories/ocert-2016-001.html

EPSS

Процентиль: 69%
0.00609
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

redhat
больше 9 лет назад

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

CVSS3: 9.8
nvd
почти 9 лет назад

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

CVSS3: 9.8
github
больше 7 лет назад

Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request

EPSS

Процентиль: 69%
0.00609
Низкий
Уязвимость CVE-2016-4800