Mortbay Jetty Discloses JSP Source Code
Moderate severity
GitHub Reviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Sep 18, 2023
Description
Published by the National Vulnerability Database
Nov 22, 2005
Published to the GitHub Advisory Database
May 1, 2022
Reviewed
Sep 18, 2023
Last updated
Sep 18, 2023
Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash (
%5C
) characters. NOTE: this might be the same issue as CVE-2006-2758.References