SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-12536

In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad…

MEDIUM 5.3EPSS 4.27%

Does this matter?

Lower severity and a low EPSS score (4.27%). Track it; it rarely justifies an emergency change on its own.

Description

In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using. If this InvalidPathException is then handled by the default Error Handler, the InvalidPathException message is included in the error response, revealing the full server path to the requesting system.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
4.27% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-209
Affected
eclipse/jetty · oracle/retail xstore point of service
Source
emo@eclipse.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.