ZeroHour

CVE-2016-4800

CVSS 3.0
9.8 critical
EPSS
6%p93
Published
()
Modified
Description

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

Vendors
eclipse
Products
jetty
Weakness
CWE-284
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.