CVE-2016-4800
Published · Updated
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 6.4%
from disclosure to weapon
Published on NVDApr 13
VulnCheck+3385d
exploitation probability
6.4%top 7% of all CVEs
observed exploitation
yesVulnCheck
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.
Affected products
n/a · n/aReferences
http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00092.htmlhttps://security.netapp.com/advisory/ntap-20190307-0006/https://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://www.ocert.org/advisories/ocert-2016-001.htmlhttp://www.securityfocus.com/bid/90945http://www.zerodayinitiative.com/advisories/ZDI-16-362