CVE-2007-6672: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
(updated )
Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple ‘/’ (slash) characters in the URI.
References
- github.com/advisories/GHSA-4jjw-xrr6-9v3p
- nvd.nist.gov/vuln/detail/CVE-2007-6672
- web.archive.org/web/20080113051254/http://www.kb.cert.org/vuls/id/553235
- web.archive.org/web/20080120225723/http://jira.codehaus.org/browse/JETTY-386
- web.archive.org/web/20080120225728/http://jira.codehaus.org/browse/JETTY/fixforversion/13950
- web.archive.org/web/20080517012615/http://www.securityfocus.com/bid/27117
Detect and mitigate CVE-2007-6672 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →