« Volver al listado

CVE-2016-4800

Estado: ModificadaCrítica (9.8)—

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-4800",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-04-13T14:59:01.760",
  "references": [
    {
      "url": "http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00092.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ocert.org/advisories/ocert-2016-001.html",
      "tags": [
        "Mitigation",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/90945",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-16-362",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20190307-0006/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpuoct2020.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00092.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ocert.org/advisories/ocert-2016-001.html",
      "tags": [
        "Mitigation",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/90945",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-16-362",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20190307-0006/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpuoct2020.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes."
    },
    {
      "lang": "es",
      "value": "El mecanismo de normalización de ruta en la clase PathResource en Eclipse Jetty 9.3.x en versiones anteriores a 9.3.9 en Windows permite a los atacantes remotos evitar las restricciones de recursos protegidos y otras restricciones de seguridad a través de una URL con ciertos caracteres de escape relacionados con las barras invertidas."
    }
  ],
  "lastModified": "2026-06-17T00:48:14.447",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7605C60A-0D9A-41A2-8E0B-CEB2E90C2237"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.0:m0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D363BB7B-FD7C-4DD9-A11E-8A6AF60DA477"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.0:m1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A27520A-7A24-47EC-8D04-0F40D50FC094"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.0:maintenance2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0AD7F68-96BD-442F-BC36-091D19BC1AC9"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.0:rc0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34269139-FB46-4EF8-BE3A-7B130F25B5E5"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77FD0118-11CC-41AB-9B12-030B1F6F8EBF"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DEC6F8B9-E2DD-4DE4-BB0F-C95ED7DDF22E"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69C3DCA8-D799-49DA-A39D-45FCC61AAE54"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "95B2E1B9-8D35-4ADF-BD4F-53F9F4FACB24"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4873E1F-1971-4911-8900-6E85C6D10C3C"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.4:rc0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D040A9F-5FE2-48DB-BD7D-83DDB4CE8B8B"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.4:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD6F208D-C7B2-4C3C-9FF7-6BF6618D2DCE"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "838EDF65-F86B-4C7A-AD0F-284736A55491"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B685174-FFD1-42F9-B969-85887C95825E"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F52CBEE-ADD5-4EE2-A24B-A0DFF10B5747"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.7:rc0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "327C5D1A-2CB7-4F0C-B0CB-4D8CBB068D77"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.7:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E70AB03E-BE50-43B1-B6BA-BFEFFEE73D94"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F08F12D-2D6B-4D03-9475-BD3E16DBA247"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:9.3.8:rc0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DEB8AEEB-77E4-41E7-A097-2A3DE29DF89B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2CF61F35-5905-4BA9-AD7E-7DB261D2F256"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}