CVE-2009-4611
Mort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace data without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Mort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace data without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator, related to (1) a string value in the Age parameter to the default URI for the Cookie Dump Servlet in test-jetty-webapp/src/main/java/com/acme/CookieDump.java under cookie/, (2) an alphabetic value in the A parameter to jsp/expr.jsp, or (3) an alphabetic value in the Content-Length HTTP header to an arbitrary application.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 3.18% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- mortbay/jetty
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/508830/100/0/threaded
- http://www.ush.it/team/ush/hack-jetty6x7x/jetty-adv.txtExploit
- http://www.ush.it/team/ush/hack_httpd_escape/adv.txtExploit
- http://www.securityfocus.com/archive/1/508830/100/0/threaded
- http://www.ush.it/team/ush/hack-jetty6x7x/jetty-adv.txtExploit
- http://www.ush.it/team/ush/hack_httpd_escape/adv.txtExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.