Directory traversal in Mort Bay Jetty
Moderate severity
GitHub Reviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Aug 3, 2023
Package
Affected versions
< 6.1.17
>= 7.0.0.M0, < 7.0.0.M2
Patched versions
6.1.17
7.0.0.M2
Description
Published by the National Vulnerability Database
May 5, 2009
Published to the GitHub Advisory Database
May 2, 2022
Reviewed
Aug 3, 2023
Last updated
Aug 3, 2023
Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.
References