Jetty Double-Slash Request Arbitrary File Access Vulnerability
BID:4360
Info
Jetty Double-Slash Request Arbitrary File Access Vulnerability
| Bugtraq ID: | 4360 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 25 2002 12:00AM |
| Updated: | Mar 25 2002 12:00AM |
| Credit: | Vulnerability reported by the Jetty Project. |
| Vulnerable: |
Jetty Jetty 3.1.6 |
| Not Vulnerable: |
Jetty Jetty 3.1.7 |
Discussion
Jetty Double-Slash Request Arbitrary File Access Vulnerability
Jetty is a freely available, open source HTTP server written in Java. It is maintained and distributed by the Jetty Project. It is available for the Unix, Linux, and Microsoft Windows platforms.
Under some circumstances, it may be possible for a remote user to gain access to the source of files in the web root directory. This is due to the improper handling of double-slashes (//) embedded in a URL. An attacker embedding double-slashes into a URL may be able to bypass the security checks placed on visitors, allowing access to a file directly, as long as the path to the file is known.
Jetty is a freely available, open source HTTP server written in Java. It is maintained and distributed by the Jetty Project. It is available for the Unix, Linux, and Microsoft Windows platforms.
Under some circumstances, it may be possible for a remote user to gain access to the source of files in the web root directory. This is due to the improper handling of double-slashes (//) embedded in a URL. An attacker embedding double-slashes into a URL may be able to bypass the security checks placed on visitors, allowing access to a file directly, as long as the path to the file is known.
Exploit / POC
Jetty Double-Slash Request Arbitrary File Access Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Jetty Double-Slash Request Arbitrary File Access Vulnerability
Solution:
Fixed version available:
Jetty Jetty 3.1.6
Solution:
Fixed version available:
Jetty Jetty 3.1.6
-
Jetty Jetty-3.1.7.tgz
http://prdownloads.sourceforge.net/jetty/Jetty-3.1.7.tgz