Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-12536

Опубликовано: 27 июн. 2018
Источник: redhat
CVSS3: 3.7

Описание

In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using. If this InvalidPathException is then handled by the default Error Handler, the InvalidPathException message is included in the error response, revealing the full server path to the requesting system.

Меры по смягчению последствий

Information disclosure occurs when java.nio.file.InvalidPathException occurs and is handled by the default Jetty error handler. To protect against this, a custom error handler can be configured for that particular error or for a larger set of errors according to the documentation link below. Red Hat Product Security advises that production deployments on Jetty use custom error handlers to limit the information disclosed and to ensure effective logging of error conditions. http://www.eclipse.org/jetty/documentation/current/custom-error-pages.html

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6jetty-eclipseNot affected
Red Hat Enterprise Linux 7jettyWill not fix
Red Hat Fuse 7jettyAffected
Red Hat JBoss Fuse 6jettyWill not fix
Red Hat Satellite 5jettyWill not fix
Red Hat Software Collectionsrh-java-common-jettyWill not fix
Red Hat Fuse 7.6.0FixedRHSA-2020:098326.03.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=1597418jetty: full server path revealed when using the default Error Handling

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using. If this InvalidPathException is then handled by the default Error Handler, the InvalidPathException message is included in the error response, revealing the full server path to the requesting system.

CVSS3: 5.3
nvd
больше 7 лет назад

In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using. If this InvalidPathException is then handled by the default Error Handler, the InvalidPathException message is included in the error response, revealing the full server path to the requesting system.

CVSS3: 5.3
debian
больше 7 лет назад

In Eclipse Jetty Server, all 9.x versions, on webapps deployed using d ...

CVSS3: 5.3
github
больше 7 лет назад

Eclipse Jetty Server generates error message containing sensitive information

CVSS3: 5.3
fstec
больше 7 лет назад

Уязвимость компонента DefaultServlet HTTP-сервера Jetty, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

3.7 Low

CVSS3