CVE-2021-28169

Description

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to /concat/%2557EB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
90.26

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-28169 are fixed in Eclipse-jetty-servlets 9.4.41Windows
Vulnerabilities CVE-2021-28169 are fixed in Eclipse-jetty-servlets 10.0.3Windows
Vulnerabilities CVE-2021-28169 are fixed in Eclipse-jetty-servlets 11.0.3Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.3Windows
Multiple Vulnerabilities are affected in IBM Security Verify Directory Integrator 10.0.0Windows
Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.6Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.5Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.1.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 24.0.1Windows
Multiple Vulnerabilities are affected in IBM MQ 9.1Windows
Multiple Vulnerabilities are affected in IBM MQ 9.2Windows
Vulnerabilities CVE-2021-28169 are fixed in Eclipse-jetty-servlets for Linux 9.4.41Linux
Vulnerabilities CVE-2021-28169 are fixed in Eclipse-jetty-servlets for Linux 10.0.3Linux
Vulnerabilities CVE-2021-28169 are fixed in Eclipse-jetty-servlets for Linux 11.0.3Linux
CVE-2021-28169NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234