{"id":"GHSA-872g-2h8h-362q","summary":"Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request","details":"The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.","aliases":["CVE-2016-4800"],"modified":"2024-02-16T08:22:06.138962Z","published":"2018-10-19T16:16:16Z","database_specific":{"github_reviewed_at":"2020-06-16T21:24:37Z","nvd_published_at":null,"cwe_ids":["CWE-284"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-4800"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-872g-2h8h-362q"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20190307-0006"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"WEB","url":"http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00092.html"},{"type":"WEB","url":"http://www.ocert.org/advisories/ocert-2016-001.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/90945"},{"type":"WEB","url":"http://www.zerodayinitiative.com/advisories/ZDI-16-362"}],"affected":[{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.3.0"},{"fixed":"9.3.9"}]}],"versions":["9.3.0.v20150612","9.3.1.v20150714","9.3.2.v20150730","9.3.3.v20150827","9.3.4.RC0","9.3.4.RC1","9.3.4.v20151007","9.3.5.v20151012","9.3.6.v20151106","9.3.7.RC0","9.3.7.RC1","9.3.7.v20160115","9.3.8.RC0","9.3.8.v20160314","9.3.9.M0","9.3.9.M1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-872g-2h8h-362q/GHSA-872g-2h8h-362q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}