Lucene search

K
freebsdFreeBSD0832EE18-CF77-11DC-8C6A-00304881AC9A
HistoryDec 22, 2007 - 12:00 a.m.

jetty -- multiple vulnerability

2007-12-2200:00:00
vuxml.freebsd.org
17

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

0.007 Low

EPSS

Percentile

79.9%

Greg Wilkins reports:

jetty allows remote attackers to bypass protection mechanisms and
read the source of files via multiple ‘/’ characters in the URI.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchjetty< 6.1.7UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

0.007 Low

EPSS

Percentile

79.9%