CVE-2021-34429

Description

For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
93.778

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-34429 are fixed in Eclipse-jetty-webapp 9.4.43Windows
Vulnerabilities CVE-2021-34429 are fixed in Eclipse-jetty-webapp 10.0.6Windows
Vulnerabilities CVE-2021-34429 are fixed in Eclipse-jetty-webapp 11.0.6Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.6Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.5Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.1.1Windows
Multiple Vulnerabilities are affected in IBM MQ 9.1Windows
Multiple Vulnerabilities are affected in IBM MQ 9.2Windows
Vulnerabilities CVE-2021-34429 are fixed in Eclipse-jetty-webapp for Linux 9.4.43Linux
Vulnerabilities CVE-2021-34429 are fixed in Eclipse-jetty-webapp for Linux 10.0.6Linux
Vulnerabilities CVE-2021-34429 are fixed in Eclipse-jetty-webapp for Linux 11.0.6Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234