QID 995380
Date Published: 2023-09-25
QID 995380: Java (Maven) Security Update for org.mortbay.jetty:jetty (GHSA-cwq3-qp8v-w8q3)
Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash (%5C) characters. NOTE: this might be the same issue as CVE-2006-2758.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-cwq3-qp8v-w8q3 for updates and patch information.
Vendor References
- GHSA-cwq3-qp8v-w8q3 -
github.com/advisories/GHSA-cwq3-qp8v-w8q3
CVEs related to QID 995380
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cwq3-qp8v-w8q3 | org.mortbay.jetty:jetty |
|