Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-872g-2h8h-362q

Опубликовано: 19 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

Пакеты

Наименование

org.eclipse.jetty:jetty-server

maven
Затронутые версииВерсия исправления

>= 9.3.0, < 9.3.9

9.3.9

EPSS

Процентиль: 69%
0.00609
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

redhat
больше 9 лет назад

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

CVSS3: 9.8
nvd
почти 9 лет назад

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

CVSS3: 9.8
debian
почти 9 лет назад

The path normalization mechanism in PathResource class in Eclipse Jett ...

EPSS

Процентиль: 69%
0.00609
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284