ZeroHour

CVE-2021-28169

CVSS 3.1
5.3 medium
EPSS
78%p100
Published
()
Modified
Description

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

Vendors
eclipsedebianoraclenetapp
Products
jetty, debian linux, communications cloud native core policy, rest data services, active iq unified manager, hci, management services for element software, snap creator framework
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news