CVE-2009-1523: Path Traversal
Common Vulnerabilities and Exposures assigned the identifiers CVE-2009-1523 and CVE-2009-1524 to the following vulnerabilities:
Name: CVE-2009-1523 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1523 Assigned: 20090505 Reference: CONFIRM: http://jira.codehaus.org/browse/JETTY-1004 Reference: CONFIRM: http://www.kb.cert.org/vuls/id/CRDY-7RKQCY Reference: CERT-VN:VU#402580 Reference: URL: http://www.kb.cert.org/vuls/id/402580 Reference: BID:34800 Reference: URL: http://www.securityfocus.com/bid/34800 Reference: SECUNIA:34975 Reference: URL: http://secunia.com/advisories/34975
Directory traversal vulnerability in the HTTP server in Mort Bay Jetty before 6.1.17, and 7.0.0.M2 and earlier 7.x versions, allows remote attackers to access arbitrary files via directory traversal sequences in the URI.
Name: CVE-2009-1524 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1524 Assigned: 20090505 Reference: CONFIRM: http://jira.codehaus.org/browse/JETTY-980 Reference: BID:34800 Reference: URL: http://www.securityfocus.com/bid/34800 Reference: SECUNIA:34975 Reference: URL: http://secunia.com/advisories/34975
Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) character.
Note: it is unclear whether or not this affects jetty 5.x, which is the version that is included in Fedora.
Other sources
Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1523?
CVE-2009-1523 has been assigned a medium severity rating due to its potential for unauthorized access.
How do I fix CVE-2009-1523?
To fix CVE-2009-1523, update the affected versions of the Jetty server to version 6.1.17 or later.
Which software is affected by CVE-2009-1523?
CVE-2009-1523 affects specific versions of the Eclipse Jetty server, including versions up to 7.0.0.M2.
What kind of vulnerability is CVE-2009-1523?
CVE-2009-1523 is a vulnerability that can allow remote attackers to bypass access controls.
When was CVE-2009-1523 discovered?
CVE-2009-1523 was disclosed in May 2009.