|
|
|
Vulnerability Note VU#553235Jetty fails to properly process URLs that contain double / charactersOverviewThe Jetty web server contains a vulnerability that may allow an attacker to access private files or directories.I. DescriptionJetty is a web server that is implemented in Java. Jetty contains a vulnerability in the way it processes URLs with multiple "/" (slash) characters. See the Jetty Double slash problem bug report for more information.II. ImpactA remote unauthenticated attacker may be able view hidden or private files and directories.III. SolutionUpgradeJetty version 6.1.7 has been released to address this issue.
References
Thanks to Greg Wilkins for reporting this vulnerability and for providing information that was used in this report. This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||