CVE-2021-28169

Scores

EPSS

0.903high90.3%
0%20%40%60%80%100%

Percentile: 90.3%

CVSS

5.3medium3.x
0246810

CVSS Score: 5.3/10

All CVSS Scores

CVSS 3.x
5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS 2.0
5.0

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Description

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to /concat?/%2557EB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhatubuntu

CWEs

CWE-200

Related Vulnerabilities

Vulnerable Software (46)

Type: Configuration

Product: jenkins

Operating System: rhel

Trait:
{  "fixed": "2.289.3.1630554997-1.el8"}

Source: redhat

Type: Configuration

Product: jetty

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty

Operating System: ubuntu trusty 14.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: jetty

Operating System: ubuntu xenial 16.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: jetty

Operating System: debian

Trait:
{  "unfixed": true}

Source: debian

Type: Configuration

Product: jetty-client

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty-continuation

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty-http

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty-io

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty-jaas

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty-javadoc

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty-jmx

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty-security

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty-server

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty-servlet

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty-util

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty-util-ajax

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty-webapp

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty-xml

Operating System: altlinux

Trait:
{  "fixed": "0:9.4.56-alt1"}

Source: redhat

Type: Configuration

Product: jetty8

Operating System: ubuntu trusty 14.04

Trait:
{  "unfixed": true}

Source: ubuntu