QID 995460

Date Published: 2023-10-03

QID 995460: Java (Maven) Security Update for org.mortbay.jetty:jetty (GHSA-9986-w5h5-vw59)

Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Github security advisory GHSA-9986-w5h5-vw59 for updates and patch information.
    Vendor References

    CVEs related to QID 995460

    Software Advisories
    Advisory ID Software Component Link
    GHSA-9986-w5h5-vw59 org.mortbay.jetty:jetty URL Logo github.com/advisories/GHSA-9986-w5h5-vw59