QID 997498
Date Published: 2024-02-26
QID 997498: Java (Maven) Security Update for org.mortbay.jetty:jetty (GHSA-qmgj-5h75-jr67)
Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2005-3747.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qmgj-5h75-jr67 for updates and patch information.
Vendor References
- GHSA-qmgj-5h75-jr67 -
github.com/advisories/GHSA-qmgj-5h75-jr67
CVEs related to QID 997498
Software Advisories
| Advisory ID | Software | Component | Link |
|---|