Arbitrary File Read Affecting org.mortbay.jetty:jetty package, versions [,6.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Not Defined
EPSS
0.87% (83rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGMORTBAYJETTY-32088
  • published19 Feb 2018
  • disclosed6 Jan 2006
  • creditUnknown

Introduced: 6 Jan 2006

CVE-2006-2759  (opens in a new tab)
CWE-264  (opens in a new tab)

How to fix?

Upgrade org.mortbay.jetty:jetty to version 6.1 or higher.

Overview

org.mortbay.jetty:jetty is a Java HTTP (Web) server and Java Servlet container.

Affected versions of this package are vulnerable to Arbitrary File Read. The software does not properly validate user-supplied input. A remote user can supply a specially crafted request to view files on target system that are located outside of the document directory. A remote user can also view script source code.

References

CVSS Scores

version 3.1