Another reference

patch-1
Noam Rathaus 2021-06-09 09:43:04 +03:00
parent 27db48cb53
commit 46e4d47d92
1 changed files with 1 additions and 0 deletions

View File

@ -6,6 +6,7 @@ info:
severity: high
reference: |
- https://github.com/eclipse/jetty.project/security/advisories/GHSA-gwcr-j4wh-j3cq
- https://github.com/eclipse/jetty.project/security/advisories/GHSA-v7ff-8wcx-gmc5
description: |
Requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory. For example a request to the ConcatServlet with a URI of /concat?/%2557EB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.