CVE-2021-28164

Aliases:GHSA-v7ff-8wcx-gmc5
Modified
Published: 01 Apr 2021, 14:20
Last modified:03 Aug 2024, 21:40

Vulnerability Summary

Overall Risk (default)
high
50/100
CVSS Score
5.3 MEDIUM
v3.1 (cve.org)
EPSS Score
93.48% CRITICAL
93% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected

Timeline

01 Apr 2021, 14:20
Published
Vulnerability first disclosed
03 Aug 2024, 21:40
Last Modified
Vulnerability information updated

Description

In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 93.48% Percentile: 100%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

  • CWE-551Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

    If a web server does not fully parse requested URLs before it examines them for authorization, it may be possible for an attacker to bypass authorization protection.

Affected Systems

  • eclipsejetty

    9.4.37:20210219 | 9.4.38:20210224

  • org.eclipse.jettyjetty-webapp

    ≥ 9.4.37, < 9.4.39

  • netappcloud_manager

    na

  • netappe-series_performance_analyzer

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0, ≤ 11.70.1

  • netappe-series_santricity_web_services

    na

  • netappelement_plug-in_for_vcenter_server

    na

  • netappsantricity_cloud_connector

    na

  • netappsnapcenter

    na

  • netappsnapcenter_plug-in

    na

  • netappstorage_replication_adapter_for_clustered_data_ontap

    ≥ 9.6

  • netappvasa_provider_for_clustered_data_ontap

    ≥ 9.6

  • netappvirtual_storage_console

    ≥ 9.6

  • oracleautovue_for_agile_product_lifecycle_management

    21.0.2

  • oraclebanking_apis

    20.1 | 21.1

  • oraclebanking_digital_experience

    20.1 | 21.1

  • oraclecommunications_session_route_manager

    ≥ 8.0.0, ≤ 8.2.4

  • oraclesiebel_core_-_automation

    ≤ 21.9

  • the eclipse foundationeclipse jetty

    ≥ 9.4.37.v20210219, < unspecified | ≥ unspecified, ≤ 9.4.38.v20210224

References (47)