Directory traversal in Mort Bay Jetty
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          May 2, 2022 
          to the GitHub Advisory Database
          •
          Updated Aug 3, 2023 
      
  
Package
Affected versions
< 6.1.17
      >= 7.0.0.M0, < 7.0.0.M2
  Patched versions
6.1.17
      7.0.0.M2
  Description
        Published by the National Vulnerability Database
      May 5, 2009 
    
  
        Published to the GitHub Advisory Database
      May 2, 2022 
    
  
        Reviewed
      Aug 3, 2023 
    
  
        Last updated
      Aug 3, 2023 
    
  
Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.
References