Jetty 9.3.8 Path Sanitization

Discussion in 'News Aggregator' started by Packet Storm, 31 May 2016.

  1. Packet Storm

    Packet Storm Guest

    The Jetty path normalization mechanism suffers of an implementation issue when parsing the request URLs. The path normalization logic implemented in the PathResource class and introduced in Jetty versions 9.3.x can be defeated by requesting malicious URLs containing specific escaped characters. Leveraging on this weakness, a malicious user can gain access to protected resources (e.g. WEB-INF and META-INF folders and their contents) and defeat application filters or other security constraints implemented in the servlet configuration. Versions 9.3.0 through 9.3.8 are affected.

    Continue reading...
     

Share This Page

Loading...