CVE-2018-12536
Summary
| CVE | CVE-2018-12536 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-27 17:29:00 UTC |
| Updated | 2023-11-07 02:52:00 UTC |
| Description | In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using. If this InvalidPathException is then handled by the default Error Handler, the InvalidPathException message is included in the error response, revealing the full server path to the requesting system. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Eclipse | Jetty | All | All | All | All |
| Application | Eclipse | Jetty | All | All | All | All |
| Application | Eclipse | Jetty | All | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 15.0 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 16.0.0 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 17.0 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 7.1 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 15.0 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 16.0.0 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 17.0 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 7.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 2661-1] jetty9 security update | MLIST | lists.debian.org | |
| Jetty Multiple Flaws Let Remote Users Conduct HTTP Request Smuggling and Session Hijacking Attacks and Determine the Installation Path - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| 535670 – (CVE-2018-12536) Jetty: CVE Request: InvalidPathException message | CONFIRM | bugs.eclipse.org | Vendor Advisory |
| Document Display | HPE Support Center | CONFIRM | support.hpe.com | Third Party Advisory |
| Oracle Critical Patch Update Advisory - October 2020 | MISC | www.oracle.com | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | Mailing List, Third Party Advisory |
| September 2018 Eclipse Jetty Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| Oracle Critical Patch Update - October 2019 | MISC | www.oracle.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.