Jetty URL Encoded Backslash Source Code Disclosure Vulnerability
BID:15515
Info
Jetty URL Encoded Backslash Source Code Disclosure Vulnerability
| Bugtraq ID: | 15515 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3747 CVE-2005-3747 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 21 2005 12:00AM |
| Updated: | Mar 19 2015 09:10AM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
Jetty Jetty 5.15 |
| Not Vulnerable: |
Jetty Jetty 5.16 |
Discussion
Jetty URL Encoded Backslash Source Code Disclosure Vulnerability
Jetty is prone to a source code disclosure vulnerability. This issue is due to a failure in the application to restrict access to sensitive files.
A successful attack causes the Web server to present the requested file as a plain text file and subsequently disclosing the source.
Versions 5.1.5. and earlier are reported to be vulnerable; the vendor has released version 5.1.6. to address this issue.
Jetty is prone to a source code disclosure vulnerability. This issue is due to a failure in the application to restrict access to sensitive files.
A successful attack causes the Web server to present the requested file as a plain text file and subsequently disclosing the source.
Versions 5.1.5. and earlier are reported to be vulnerable; the vendor has released version 5.1.6. to address this issue.
Exploit / POC
Jetty URL Encoded Backslash Source Code Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Jetty URL Encoded Backslash Source Code Disclosure Vulnerability
Solution:
The vendor has released version 5.1.6. to address this vulnerability.
Solution:
The vendor has released version 5.1.6. to address this vulnerability.
References
Jetty URL Encoded Backslash Source Code Disclosure Vulnerability
References:
References:
- Jetty Changelog for version 5.1.6. (Jetty )
- Jetty Homepage (Jetty)