The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "9.3.0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-m0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-m1"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-maintenance2"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-rc0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.4-rc0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.4-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.5"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.6"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.7"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.7-rc0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.7-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.8-rc0"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4800.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.3.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.3.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.3.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.3.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.3.8"
}
]
}
]