CVE-2021-28169

Aliases:GHSA-gwcr-j4wh-j3cq
Modified
Published: 09 Jun 2021, 01:55
Last modified:03 Aug 2024, 21:40

Vulnerability Summary

Overall Risk (default)
medium
39/100
CVSS Score
5.3 MEDIUM
v3.1 (cve.org)
EPSS Score
90.26% CRITICAL
90% probability +1.42%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jun 2021, 01:55
Published
Vulnerability first disclosed
03 Aug 2024, 21:40
Last Modified
Vulnerability information updated

Description

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 90.26% Percentile: 100%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • debiandebian_linux

    9.0 | 10.0

  • eclipsejetty

    < 9.4.41 | ≥ 10.0.0, < 10.0.3 | ≥ 11.0.0, < 11.0.3

  • org.eclipse.jettyjetty-servlets

    < 9.4.41 | ≥ 10.0.0, < 10.0.3 | ≥ 11.0.0, < 11.0.3

  • netappactive_iq_unified_manager

    na

  • netapphci

    na

  • netappmanagement_services_for_element_software

    na

  • netappsnap_creator_framework

    na

  • oraclecommunications_cloud_native_core_policy

    1.14.0

  • oraclerest_data_services

    < 21.3

  • the eclipse foundationeclipse jetty

    ≥ unspecified, ≤ 9.4.40 | ≥ unspecified, ≤ 10.0.2 | ≥ unspecified, ≤ 11.0.2

References (44)