CVE-2018-12536
Eclipse Jetty Server generates error message containing sensitive information
描述
In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using. If this InvalidPathException is then handled by the default Error Handler, the InvalidPathException message is included in the error response, revealing the full server path to the requesting system.
如何修補 CVE-2018-12536
要修補 CVE-2018-12536,請將受影響套件升級到下列已修補版本。
- —升級至 9.2.25-1 或更新版本
- —升級至 9.4.11.v20180605 或更新版本
CVE-2018-12536 正在被利用嗎?
低 — EPSS 為 4.3%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 9.2.25-1
- >= 9.4.0, < 9.4.11.v20180605
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |