7.5
CVSSv2

CVE-2016-4800

Published: 13/04/2017 Updated: 20/10/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x prior to 9.3.9 on Windows allows remote malicious users to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

Vulnerable Product Search on Vulmon Subscribe to Product

eclipse jetty 9.3.7

eclipse jetty 9.3.4

eclipse jetty 9.3.5

eclipse jetty 9.3.6

eclipse jetty 9.3.1

eclipse jetty 9.3.2

eclipse jetty 9.3.0

eclipse jetty 9.3.8

eclipse jetty 9.3.3

Vendor Advisories

The path normalization mechanism in PathResource class in Eclipse Jetty 93x before 939 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes ...

Github Repositories

Shell script to exploit a security flaw in Elvis DAM

Elvis DAM - Directory Traversal / Auth Bypass (ElvisDAM-DTsh) A vulnerability in Elvis DAM was discovered and reported to WoodWing Software in May 2018 Jetty web server used by some versions of Elvis DAM is vulnerable to path traversal attacks PathResource class introduced in Jetty 93X (CVE-2016-4800) can be bypassed by requesting malicious URLs containing specific escaped