CVE-2018-12536

unknown
Published 2018-10-19 · Modified 2024-02-16
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2
VIR risk

Description

In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using. If this InvalidPathException is then handled by the default Error Handler, the InvalidPathException message is included in the error response, revealing the full server path to the requesting system.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2018-12536

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed9.2.25-1
debian debianbullseyefixed9.2.25-1
debian debianforkyfixed9.2.25-1
debian debiansidfixed9.2.25-1
debian debiantrixiefixed9.2.25-1

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.eclipse.jetty:jetty-server>=9.4.0,<9.4.11.v201806059.4.11.v20180605
java Mavenorg.eclipse.jetty:jetty-server>=9.0.0,<9.3.24.v201806059.3.24.v20180605

References

Verify integrity in audit chain (admin only). AS-IS.