{"id":"GHSA-cwq3-qp8v-w8q3","summary":"Mortbay Jetty Discloses JSP Source Code","details":"Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash (`%5C`) characters.  NOTE: this might be the same issue as CVE-2006-2758.","aliases":["CVE-2005-3747"],"modified":"2024-11-28T05:34:11.091547Z","published":"2022-05-01T02:20:38Z","database_specific":{"cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-09-18T23:46:51Z","nvd_published_at":"2005-11-22T11:03:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3747"},{"type":"WEB","url":"http://sourceforge.net/project/shownotes.php?release_id=372086&group_id=7322"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/450315/100/0/threaded"},{"type":"WEB","url":"http://www.securityfocus.com/bid/15515"}],"affected":[{"package":{"name":"org.mortbay.jetty:jetty","ecosystem":"Maven","purl":"pkg:maven/org.mortbay.jetty/jetty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.6"}]}],"versions":["4.1-rc1","4.1-rc6","4.2.10","4.2.12","4.2.2","4.2.3","4.2.9","test-6.0.0","test-6.0.0rc3","test-6.0.0rc4","test-6.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cwq3-qp8v-w8q3/GHSA-cwq3-qp8v-w8q3.json"}}],"schema_version":"1.9.0"}