Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-4800

Опубликовано: 13 апр. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:eclipse:jetty:9.3.0:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.0:m0:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.0:m1:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.0:maintenance2:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.0:rc0:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.1:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.2:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.3:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.4:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.4:rc0:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.4:rc1:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.5:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.6:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.7:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.7:rc0:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.7:rc1:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.8:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:9.3.8:rc0:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

EPSS

Процентиль: 93%
0.06363
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

redhat
больше 10 лет назад

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

CVSS3: 9.8
debian
больше 9 лет назад

The path normalization mechanism in PathResource class in Eclipse Jett ...

CVSS3: 9.8
github
почти 8 лет назад

Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request

EPSS

Процентиль: 93%
0.06363
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-284