[MAVEN:GHSA-CWQ3-QP8V-W8Q3] Mortbay Jetty Discloses JSP Source Code

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash (%5C) characters. NOTE: this might be the same issue as CVE-2006-2758.

Package Affected Version
pkg:maven/org.mortbay.jetty/jetty < 5.1.6
Package Fixed Version
pkg:maven/org.mortbay.jetty/jetty = 5.1.6
ID
MAVEN:GHSA-CWQ3-QP8V-W8Q3
Severity
moderate
URL
https://github.com/advisories/GHSA-cwq3-qp8v-w8q3
Published
2022-05-01T02:20:38
(2 years ago)
Modified
2023-09-18T23:46:54
(12 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.mortbay.jetty/jetty org.mortbay.jetty jetty < 5.1.6
Fixed pkg:maven/org.mortbay.jetty/jetty org.mortbay.jetty jetty = 5.1.6
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...