Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-12536

Опубликовано: 27 июн. 2018
Источник: ubuntu
Приоритет: low
CVSS2: 5
CVSS3: 5.3

Описание

In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using. If this InvalidPathException is then handled by the default Error Handler, the InvalidPathException message is included in the error response, revealing the full server path to the requesting system.

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/focal

DNE

focal

DNE

Показывать по

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

9.2.25-1
cosmic

not-affected

9.2.25-1
devel

not-affected

9.2.25-1
disco

not-affected

9.2.25-1
eoan

not-affected

9.2.25-1
esm-apps/bionic

not-affected

9.2.25-1
esm-apps/focal

not-affected

9.2.25-1
esm-apps/jammy

not-affected

9.2.25-1
esm-apps/noble

not-affected

9.2.25-1

Показывать по

5 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.7
redhat
больше 7 лет назад

In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using. If this InvalidPathException is then handled by the default Error Handler, the InvalidPathException message is included in the error response, revealing the full server path to the requesting system.

CVSS3: 5.3
nvd
больше 7 лет назад

In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using. If this InvalidPathException is then handled by the default Error Handler, the InvalidPathException message is included in the error response, revealing the full server path to the requesting system.

CVSS3: 5.3
debian
больше 7 лет назад

In Eclipse Jetty Server, all 9.x versions, on webapps deployed using d ...

CVSS3: 5.3
github
больше 7 лет назад

Eclipse Jetty Server generates error message containing sensitive information

CVSS3: 5.3
fstec
больше 7 лет назад

Уязвимость компонента DefaultServlet HTTP-сервера Jetty, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

5 Medium

CVSS2

5.3 Medium

CVSS3