CVE-2018-12536: Eclipse Jetty

Medium severity, CVSS 5.3. EPSS: 4.4% chance of exploitation in the next 30 days.

In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using. If this InvalidPathException is then handled by the default Error Handler, the InvalidPathException message is included in the error response, revealing the full server path to the requesting system.

Affected products

  • Eclipse Jetty: from 9.0.0, up to and including 9.2.26; from 9.3.0, before 9.3.24 (fixed in 9.3.24); from 9.4.0, before 9.4.11 (fixed in 9.4.11)
  • Oracle Retail Xstore Point Of Service: version 7.1 only; version 15.0 only; version 16.0.0 only; version 17.0 only

Published 2018-06-27. Last modified 2026-06-17.