Overview
The Jetty web server contains a vulnerability that may allow an attacker to access private files or directories.
Description
Jetty is a web server that is implemented in Java. Jetty contains a vulnerability in the way it processes URLs with multiple "/" (slash) characters. See the Jetty Double slash problem bug report for more information. |
Impact
A remote unauthenticated attacker may be able view hidden or private files and directories. |
Solution
Upgrade Jetty version 6.1.7 has been released to address this issue. |
|
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental |
References
Acknowledgements
Thanks to Greg Wilkins for reporting this vulnerability and for providing information that was used in this report.
This document was written by Ryan Giobbi.
Other Information
| CVE IDs: | CVE-2007-6672 |
| Severity Metric: | 2.64 |
| Date Public: | 2007-12-28 |
| Date First Published: | 2008-01-03 |
| Date Last Updated: | 2008-01-23 20:39 UTC |
| Document Revision: | 19 |