Description
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0545 | The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes. |
Github GHSA |
GHSA-872g-2h8h-362q | Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T00:39:26.308Z
Reserved: 2016-05-13T00:00:00.000Z
Link: CVE-2016-4800
No data.
Status : Modified
Published: 2017-04-13T14:59:01.760
Modified: 2026-05-13T00:24:29.033
Link: CVE-2016-4800
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA