CVE-2016-4800

critical
Published 2017-04-13 · Modified 2024-02-16
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-4800

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.ocert.org/advisories/ocert-2016-001.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://dev.eclipse.org/mhonarc/lists/jetty-announce/msg00092.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.eclipse.jetty:jetty-server>=9.3.0,<9.3.99.3.9

Application impact

VendorProductVersionsFixed
eclipsejetty9.3.0
eclipsejetty9.3.1
eclipsejetty9.3.2
eclipsejetty9.3.3
eclipsejetty9.3.4
eclipsejetty9.3.5
eclipsejetty9.3.6
eclipsejetty9.3.7
eclipsejetty9.3.8

References

CWEs

CWE-284

Verify integrity in audit chain (admin only). AS-IS.