MEDIUM
: multiple vulnerabilities in jetty
Published May 5, 2009
5.3
MEDIUMCVSS 3.1
EPSS 25.80%
Description
Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.
Affected products
No data.
OR
- ≤ 6.1.16
- ≤ 7.0.0
- 1.0
- 1.0.1
- 1.1
- 1.1.1
- 1.2.0
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.3.5
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.1.0
- 2.1.1
- 2.1.2
- 2.1.3
- 2.1.4
- 2.1.5
- 2.1.6
- 2.1.7
- 2.1.b0
- 2.1.b1
- 2.2
- 2.2
- 2.2
- 2.2
- 2.2
- 2.2
- 2.2
- 2.2.0
- 2.2.1
- 2.2.2
- 2.2.3
- 2.2.4
- 2.2.5
- 2.2.6
- 2.2.7
- 2.2.8
- 2.3.0
- 2.3.0a
- 2.3.1
- 2.3.2
- 2.3.3
- 2.3.4
- 2.3.5
- 2.4.0
- 2.4.1
- 2.4.2
- 2.4.3
- 2.4.4
- 2.4.5
- 2.4.6
- 2.4.7
- 2.4.8
- 2.4.9
- 3.0.0
- 3.0.0
- 3.0.0
- 3.0.0
- 3.0.0
- 3.0.0
- 3.0.0
- 3.0.0
- 3.0.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.a0
- 3.0.a1
- 3.0.a2
- 3.0.a3
- 3.0.a4
- 3.0.a5
- 3.0.a6
- 3.0.a7
- 3.0.a8
- 3.0.a9
- 3.0.a90
- 3.0.a91
- 3.0.a92
- 3.0.a93
- 3.0.a94
- 3.0.a95
- 3.0.a96
- 3.0.a97
- 3.0.a98
- 3.0.a99
- 3.0.b01
- 3.0.b02
- 3.0.b03
- 3.0.b04
- 3.0.b05
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1.0
- 3.1.1
- 3.1.2
- 3.1.3
- 3.1.4
- 3.1.5
- 3.1.6
- 3.1.7
- 3.1.8
- 3.1.9
- 4.0
- 4.0
- 4.0
- 4.0.0
- 4.0.1
- 4.0.1
- 4.0.1
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.4
- 4.0.5
- 4.0.6
- 4.0.b0
- 4.0.b1
- 4.0.b2
- 4.0.d0
- 4.0.d1
- 4.0.d2
- 4.0.d3
- 4.0.d4
- 4.1.0
- 4.1.0
- 4.1.0
- 4.1.0
- 4.1.0
- 4.1.0
- 4.1.0
- 4.1.0
- 4.1.1
- 4.1.2
- 4.1.3
- 4.1.4
- 4.1.b0
- 4.1.b1
- 4.1.d0
- 4.1.d1
- 4.1.d2
- 4.2.0
- 4.2.0
- 4.2.0
- 4.2.0
- 4.2.1
- 4.2.2
- 4.2.3
- 4.2.4
- 4.2.4
- 4.2.5
- 4.2.6
- 4.2.7
- 4.2.8_01
- 4.2.9
- 4.2.9
- 4.2.9
- 4.2.10
- 4.2.10
- 4.2.10
- 4.2.10
- 4.2.12
- 4.2.14
- 4.2.14
- 4.2.14
- 4.2.15
- 4.2.15
- 4.2.16
- 4.2.17
- 4.2.18
- 4.2.19
- 4.2.20
- 4.2.20
- 4.2.21
- 4.2.22
- 4.2.23
- 4.2.23
- 4.2.24
- 4.2.24
- 4.2.24
- 4.2.25
- 4.2.26
- 4.2.27
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0.0
- 5.0.0
- 5.1
- 5.1
- 5.1.0
- 5.1.1
- 5.1.1
- 5.1.1
- 5.1.2
- 5.1.2
- 5.1.3
- 5.1.3
- 5.1.3
- 5.1.3
- 5.1.3
- 5.1.3
- 5.1.4
- 5.1.4
- 5.1.5
- 5.1.5
- 5.1.5
- 5.1.5
- 5.1.6
- 5.1.7
- 5.1.7
- 5.1.8
- 5.1.9
- 5.1.10
- 5.1.11
- 5.1.11
- 5.1.12
- 5.1.13
- 5.1.14
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.0
- 6.0.1
- 6.0.2
- 6.1.0
- 6.1.0
- 6.1.0
- 6.1.0
- 6.1.0
- 6.1.0
- 6.1.0
- 6.1.0
- 6.1.0
- 6.1.1
- 6.1.1
- 6.1.2
- 6.1.2
- 6.1.2
- 6.1.2
- 6.1.2
- 6.1.2
- 6.1.2
- 6.1.2
- 6.1.2
- 6.1.3
- 6.1.4
- 6.1.4
- 6.1.4
- 6.1.5
- 6.1.5
- 6.1.6
- 6.1.6
- 6.1.6
- 6.1.7
- 6.1.8
- 6.1.9
- 6.1.10
- 6.1.11
- 6.1.12
- 6.1.12
- 6.1.12
- 6.1.12
- 6.1.12
- 6.1.12
- 6.1.14
- 6.1.15
- 6.1.15
- 6.1.15
- 6.1.15
- 6.1.15
- 6.1.15
- 7.0.0
- 7.0.0
- 7.0.0
- 7.0.0
- 7.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (23)
- http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282388 vendor-advisoryx_refsource_HP
- http://jira.codehaus.org/browse/JETTY-1004 x_refsource_CONFIRM
- http://secunia.com/advisories/34975 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35143 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35225 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35776 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/40553 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.kb.cert.org/vuls/id/402580 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.kb.cert.org/vuls/id/CRDY-7RKQCY x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/34800 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/35675 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1022563 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2009/1900 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/1792 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-1523 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=499867 x_refsource_CONFIRMIssue Tracking
- https://github.com/advisories/GHSA-9986-w5h5-vw59 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-1523
- https://www.cve.org/CVERecord?id=CVE-2009-1523
- https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01257.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01259.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01262.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 5, 2009
Updated Aug 7, 2024
Reserved May 5, 2009
Link CVE-2009-1523
CISA Vulnrichment
GHSA-9986-W5H5-VW59 Updated n/a