Vulnerable Libraries - jetty-util-9.0.0.v20130308.jar, jetty-server-9.2.9.v20150224.jar, jetty-server-9.0.7.v20131107.jar, jetty-server-9.0.0.v20130308.jar, jetty-server-9.3.6.v20151106.jar, jetty-server-9.3.2.v20150730.jar, jetty-util-9.2.9.v20150224.jar, jetty-server-9.1.0.v20131115.jar, jetty-util-9.1.0.v20131115.jar, jetty-util-9.3.6.v20151106.jar, jetty-util-9.2.15.v20160210.jar, jetty-util-9.2.12.v20150709.jar, jetty-util-9.0.7.v20131107.jar, jetty-util-9.3.2.v20150730.jar
jetty-util-9.0.0.v20130308.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/jetty-9/jetty-9.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.0.0.v20130308/19859238118e33ad1be4c0b629fe69c0f73853f4/jetty-util-9.0.0.v20130308.jar
Dependency Hierarchy:
- jetty-server-9.0.0.v20130308.jar (Root Library)
- jetty-io-9.0.0.v20130308.jar
- ❌ jetty-util-9.0.0.v20130308.jar (Vulnerable Library)
jetty-server-9.2.9.v20150224.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/dropwizard/dropwizard.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.2.9.v20150224/d30a52e992c3484569f58763f55097a1da3202ee/jetty-server-9.2.9.v20150224.jar
Dependency Hierarchy:
- dropwizard-testing-0.8.0.jar (Root Library)
- dropwizard-core-0.8.0.jar
- dropwizard-jersey-0.8.0.jar
- ❌ jetty-server-9.2.9.v20150224.jar (Vulnerable Library)
jetty-server-9.0.7.v20131107.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/dropwizard/dropwizard-views/dropwizard-views.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.0.7.v20131107/682ae23f9e4a5e397d96f215b62641755d2a59b7/jetty-server-9.0.7.v20131107.jar
Dependency Hierarchy:
- dropwizard-views-0.7.0.jar (Root Library)
- dropwizard-core-0.7.0.jar
- dropwizard-lifecycle-0.7.0.jar
- ❌ jetty-server-9.0.7.v20131107.jar (Vulnerable Library)
jetty-server-9.0.0.v20130308.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/jetty-9/jetty-9.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.0.0.v20130308/157403813bb93758f9281e299ec458e6ef5e0aa/jetty-server-9.0.0.v20130308.jar,/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.0.0.v20130308/157403813bb93758f9281e299ec458e6ef5e0aa/jetty-server-9.0.0.v20130308.jar
Dependency Hierarchy:
- ❌ jetty-server-9.0.0.v20130308.jar (Vulnerable Library)
jetty-server-9.3.6.v20151106.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/sparkjava-2.3/sparkjava-2.3.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.3.6.v20151106/d9c43a1b20ede7e3c456237d71b4cce1dff5457a/jetty-server-9.3.6.v20151106.jar
Dependency Hierarchy:
- spark-core-2.4.jar (Root Library)
- ❌ jetty-server-9.3.6.v20151106.jar (Vulnerable Library)
jetty-server-9.3.2.v20150730.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/sparkjava-2.3/sparkjava-2.3.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.3.2.v20150730/d53622049200cee5c344b29c848d581aa876f93e/jetty-server-9.3.2.v20150730.jar
Dependency Hierarchy:
- spark-core-2.3.jar (Root Library)
- ❌ jetty-server-9.3.2.v20150730.jar (Vulnerable Library)
jetty-util-9.2.9.v20150224.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/dropwizard/dropwizard.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.2.9.v20150224/b5fb774a02158e9f66fed949581159a8d0dfcbe1/jetty-util-9.2.9.v20150224.jar
Dependency Hierarchy:
- dropwizard-testing-0.8.0.jar (Root Library)
- dropwizard-core-0.8.0.jar
- dropwizard-logging-0.8.0.jar
- ❌ jetty-util-9.2.9.v20150224.jar (Vulnerable Library)
jetty-server-9.1.0.v20131115.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/jetty-client-9.1/jetty-client-9.1.gradle
Path to vulnerable library: /caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.1.0.v20131115/c64cb3ab62ff32fcd8b838369a426c688d901103/jetty-server-9.1.0.v20131115.jar
Dependency Hierarchy:
- ❌ jetty-server-9.1.0.v20131115.jar (Vulnerable Library)
jetty-util-9.1.0.v20131115.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/jetty-client-9.1/jetty-client-9.1.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.1.0.v20131115/440fc44218366a7b58739aef4402b4927e135b9c/jetty-util-9.1.0.v20131115.jar,/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.1.0.v20131115/440fc44218366a7b58739aef4402b4927e135b9c/jetty-util-9.1.0.v20131115.jar
Dependency Hierarchy:
- ❌ jetty-util-9.1.0.v20131115.jar (Vulnerable Library)
jetty-util-9.3.6.v20151106.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/sparkjava-2.3/sparkjava-2.3.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.3.6.v20151106/8721c8e670c11ea19005c567733453956b6243fc/jetty-util-9.3.6.v20151106.jar
Dependency Hierarchy:
- spark-core-2.4.jar (Root Library)
- jetty-server-9.3.6.v20151106.jar
- jetty-io-9.3.6.v20151106.jar
- ❌ jetty-util-9.3.6.v20151106.jar (Vulnerable Library)
jetty-util-9.2.15.v20160210.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-smoke-tests/play-2.5/play-2.5.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.2.15.v20160210/ccd245541cc63311bdcfe551525bd7d82ea5e92c/jetty-util-9.2.15.v20160210.jar
Dependency Hierarchy:
- play-test_2.11-2.5.19.jar (Root Library)
- htmlunit-2.20.jar
- websocket-client-9.2.15.v20160210.jar
- ❌ jetty-util-9.2.15.v20160210.jar (Vulnerable Library)
jetty-util-9.2.12.v20150709.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-smoke-tests/play-2.4/play-2.4.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.2.12.v20150709/d99d38adfdb5ec677643f04fa862554b0bb8b42e/jetty-util-9.2.12.v20150709.jar
Dependency Hierarchy:
- play-test_2.11-2.4.11.jar (Root Library)
- fluentlenium-core-0.10.9.jar
- selenium-java-2.48.2.jar
- selenium-htmlunit-driver-2.48.2.jar
- htmlunit-2.18.jar
- websocket-client-9.2.12.v20150709.jar
- ❌ jetty-util-9.2.12.v20150709.jar (Vulnerable Library)
jetty-util-9.0.7.v20131107.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/dropwizard/dropwizard-views/dropwizard-views.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.0.7.v20131107/93a606c83b047e8855eb3af68c335e60fa757367/jetty-util-9.0.7.v20131107.jar
Dependency Hierarchy:
- dropwizard-views-0.7.0.jar (Root Library)
- dropwizard-core-0.7.0.jar
- dropwizard-lifecycle-0.7.0.jar
- jetty-server-9.0.7.v20131107.jar
- jetty-io-9.0.7.v20131107.jar
- ❌ jetty-util-9.0.7.v20131107.jar (Vulnerable Library)
jetty-util-9.3.2.v20150730.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/sparkjava-2.3/sparkjava-2.3.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.3.2.v20150730/96eab74d8886ee9d51b6a3eeab9744807e842169/jetty-util-9.3.2.v20150730.jar
Dependency Hierarchy:
- spark-core-2.3.jar (Root Library)
- jetty-webapp-9.3.2.v20150730.jar
- jetty-xml-9.3.2.v20150730.jar
- ❌ jetty-util-9.3.2.v20150730.jar (Vulnerable Library)
Found in HEAD commit: 2819174635979a19573ec0ce8e3e2b63a3848079
Found in base branch: master
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4800
Release Date: 2017-04-13
Fix Resolution (org.eclipse.jetty:jetty-util): 9.2.25.v20180606
Direct dependency fix Resolution (org.eclipse.jetty:jetty-server): 9.2.25.v20180606
Fix Resolution (org.eclipse.jetty:jetty-server): 9.2.25.v20180606
Direct dependency fix Resolution (io.dropwizard:dropwizard-testing): 1.0.0
Fix Resolution (org.eclipse.jetty:jetty-server): 9.3.9.M0
Direct dependency fix Resolution (com.sparkjava:spark-core): 2.6.0
Fix Resolution (org.eclipse.jetty:jetty-server): 9.3.9.M0
Direct dependency fix Resolution (com.sparkjava:spark-core): 2.6.0
Fix Resolution (org.eclipse.jetty:jetty-util): 9.2.25.v20180606
Direct dependency fix Resolution (io.dropwizard:dropwizard-testing): 1.0.0
Fix Resolution (org.eclipse.jetty:jetty-util): 9.3.9.M0
Direct dependency fix Resolution (com.sparkjava:spark-core): 2.6.0
Fix Resolution (org.eclipse.jetty:jetty-util): 9.2.25.v20180606
Direct dependency fix Resolution (com.typesafe.play:play-test_2.11): 2.6.0
Fix Resolution (org.eclipse.jetty:jetty-util): 9.2.25.v20180606
Direct dependency fix Resolution (com.typesafe.play:play-test_2.11): 2.6.0
Fix Resolution (org.eclipse.jetty:jetty-util): 9.3.9.M0
Direct dependency fix Resolution (com.sparkjava:spark-core): 2.6.0
CVE-2016-4800 - High Severity Vulnerability
jetty-util-9.0.0.v20130308.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/jetty-9/jetty-9.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.0.0.v20130308/19859238118e33ad1be4c0b629fe69c0f73853f4/jetty-util-9.0.0.v20130308.jar
Dependency Hierarchy:
jetty-server-9.2.9.v20150224.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/dropwizard/dropwizard.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.2.9.v20150224/d30a52e992c3484569f58763f55097a1da3202ee/jetty-server-9.2.9.v20150224.jar
Dependency Hierarchy:
jetty-server-9.0.7.v20131107.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/dropwizard/dropwizard-views/dropwizard-views.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.0.7.v20131107/682ae23f9e4a5e397d96f215b62641755d2a59b7/jetty-server-9.0.7.v20131107.jar
Dependency Hierarchy:
jetty-server-9.0.0.v20130308.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/jetty-9/jetty-9.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.0.0.v20130308/157403813bb93758f9281e299ec458e6ef5e0aa/jetty-server-9.0.0.v20130308.jar,/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.0.0.v20130308/157403813bb93758f9281e299ec458e6ef5e0aa/jetty-server-9.0.0.v20130308.jar
Dependency Hierarchy:
jetty-server-9.3.6.v20151106.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/sparkjava-2.3/sparkjava-2.3.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.3.6.v20151106/d9c43a1b20ede7e3c456237d71b4cce1dff5457a/jetty-server-9.3.6.v20151106.jar
Dependency Hierarchy:
jetty-server-9.3.2.v20150730.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/sparkjava-2.3/sparkjava-2.3.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.3.2.v20150730/d53622049200cee5c344b29c848d581aa876f93e/jetty-server-9.3.2.v20150730.jar
Dependency Hierarchy:
jetty-util-9.2.9.v20150224.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/dropwizard/dropwizard.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.2.9.v20150224/b5fb774a02158e9f66fed949581159a8d0dfcbe1/jetty-util-9.2.9.v20150224.jar
Dependency Hierarchy:
jetty-server-9.1.0.v20131115.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/jetty-client-9.1/jetty-client-9.1.gradle
Path to vulnerable library: /caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.1.0.v20131115/c64cb3ab62ff32fcd8b838369a426c688d901103/jetty-server-9.1.0.v20131115.jar
Dependency Hierarchy:
jetty-util-9.1.0.v20131115.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/jetty-client-9.1/jetty-client-9.1.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.1.0.v20131115/440fc44218366a7b58739aef4402b4927e135b9c/jetty-util-9.1.0.v20131115.jar,/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.1.0.v20131115/440fc44218366a7b58739aef4402b4927e135b9c/jetty-util-9.1.0.v20131115.jar
Dependency Hierarchy:
jetty-util-9.3.6.v20151106.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/sparkjava-2.3/sparkjava-2.3.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.3.6.v20151106/8721c8e670c11ea19005c567733453956b6243fc/jetty-util-9.3.6.v20151106.jar
Dependency Hierarchy:
jetty-util-9.2.15.v20160210.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-smoke-tests/play-2.5/play-2.5.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.2.15.v20160210/ccd245541cc63311bdcfe551525bd7d82ea5e92c/jetty-util-9.2.15.v20160210.jar
Dependency Hierarchy:
jetty-util-9.2.12.v20150709.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-smoke-tests/play-2.4/play-2.4.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.2.12.v20150709/d99d38adfdb5ec677643f04fa862554b0bb8b42e/jetty-util-9.2.12.v20150709.jar
Dependency Hierarchy:
jetty-util-9.0.7.v20131107.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/dropwizard/dropwizard-views/dropwizard-views.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.0.7.v20131107/93a606c83b047e8855eb3af68c335e60fa757367/jetty-util-9.0.7.v20131107.jar
Dependency Hierarchy:
jetty-util-9.3.2.v20150730.jar
Utility classes for Jetty
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /dd-java-agent/instrumentation/sparkjava-2.3/sparkjava-2.3.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/9.3.2.v20150730/96eab74d8886ee9d51b6a3eeab9744807e842169/jetty-util-9.3.2.v20150730.jar
Dependency Hierarchy:
Found in HEAD commit: 2819174635979a19573ec0ce8e3e2b63a3848079
Found in base branch: master
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.
Publish Date: 2017-04-13
URL: CVE-2016-4800
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4800
Release Date: 2017-04-13
Fix Resolution (org.eclipse.jetty:jetty-util): 9.2.25.v20180606
Direct dependency fix Resolution (org.eclipse.jetty:jetty-server): 9.2.25.v20180606
Fix Resolution (org.eclipse.jetty:jetty-server): 9.2.25.v20180606
Direct dependency fix Resolution (io.dropwizard:dropwizard-testing): 1.0.0
Fix Resolution (org.eclipse.jetty:jetty-server): 9.3.9.M0
Direct dependency fix Resolution (com.sparkjava:spark-core): 2.6.0
Fix Resolution (org.eclipse.jetty:jetty-server): 9.3.9.M0
Direct dependency fix Resolution (com.sparkjava:spark-core): 2.6.0
Fix Resolution (org.eclipse.jetty:jetty-util): 9.2.25.v20180606
Direct dependency fix Resolution (io.dropwizard:dropwizard-testing): 1.0.0
Fix Resolution (org.eclipse.jetty:jetty-util): 9.3.9.M0
Direct dependency fix Resolution (com.sparkjava:spark-core): 2.6.0
Fix Resolution (org.eclipse.jetty:jetty-util): 9.2.25.v20180606
Direct dependency fix Resolution (com.typesafe.play:play-test_2.11): 2.6.0
Fix Resolution (org.eclipse.jetty:jetty-util): 9.2.25.v20180606
Direct dependency fix Resolution (com.typesafe.play:play-test_2.11): 2.6.0
Fix Resolution (org.eclipse.jetty:jetty-util): 9.3.9.M0
Direct dependency fix Resolution (com.sparkjava:spark-core): 2.6.0
⛑️ Automatic Remediation is available for this issue