CVE-2016-4800
published 2017-04-13CVE-2016-4800: The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource…
PriorityP276critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
6.36%
93.2th percentile
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jetty9 | — | — |
| eclipse | jetty | — | — |
| eclipse | jetty | — | — |
| eclipse | jetty | — | — |
| eclipse | jetty | — | — |
| eclipse | jetty | — | — |
| eclipse | jetty | — | — |
| eclipse | jetty | — | — |
| eclipse | jetty | — | — |
| eclipse | jetty | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jetty: path normalization
vendor_redhat·2016-05-30·CVSS 9.8
CVE-2016-4800 [CRITICAL] jetty: path normalization
jetty: path normalization
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.
Package: jetty-eclipse (Red Hat Enterprise Linux 6) - Not affected
Package: jetty (Red Hat Enterprise Linux 7) - Not affected
Package: jetty (Red Hat JBoss A-MQ 6) - Not affected
Package: jetty (Red Hat JBoss BRMS 5) - Not affected
Package: jetty (Red Hat JBoss Data Virtualization 6) - Not affected
Package: jetty (Red Hat JBoss Enterprise Application Platform 5) - Not affected
Package: jetty (Red Hat JBoss Fuse 6) - Not affected
Package: jetty (Red Hat JBoss Fuse Service Works 6) - Not affected
Debian
CVE-2016-4800: jetty9 - The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x be...
vendor_debian·2016·CVSS 9.8
CVE-2016-4800 [CRITICAL] CVE-2016-4800: jetty9 - The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x be...
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request
osv·2018-10-19
CVE-2016-4800 [CRITICAL] Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request
Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.
GHSA
Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request
ghsa·2018-10-19
CVE-2016-4800 [CRITICAL] CWE-284 Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request
Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.
VulnCheck
eclipse jetty Improper Access Control
vulncheck·2016·CVSS 9.8
CVE-2016-4800 [CRITICAL] eclipse jetty Improper Access Control
eclipse jetty Improper Access Control
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.
Affected: eclipse jetty
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.f5.com/labs/articles/cve-2024-44000-litespeed-cache-account-takeover-ranks-in-june-s-top-threats
No detection rules found.
http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00092.htmlhttp://www.ocert.org/advisories/ocert-2016-001.htmlhttp://www.securityfocus.com/bid/90945http://www.zerodayinitiative.com/advisories/ZDI-16-362https://security.netapp.com/advisory/ntap-20190307-0006/https://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00092.htmlhttp://www.ocert.org/advisories/ocert-2016-001.htmlhttp://www.securityfocus.com/bid/90945http://www.zerodayinitiative.com/advisories/ZDI-16-362https://security.netapp.com/advisory/ntap-20190307-0006/https://www.oracle.com/security-alerts/cpuoct2020.html
2017-04-13
Published
Exploited in the wild