In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Eclipse
Subscribe
|
Jetty
Subscribe
|
|
Netapp
Subscribe
|
Cloud Manager
Subscribe
E-series Performance Analyzer
Subscribe
E-series Santricity Os Controller
Subscribe
E-series Santricity Web Services
Subscribe
Element Plug-in For Vcenter Server
Subscribe
Santricity Cloud Connector
Subscribe
Snapcenter
Subscribe
Snapcenter Plug-in
Subscribe
Storage Replication Adapter For Clustered Data Ontap
Subscribe
Vasa Provider For Clustered Data Ontap
Subscribe
Virtual Storage Console
Subscribe
|
|
Oracle
Subscribe
|
|
|
Redhat
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v7ff-8wcx-gmc5 | Authorization Before Parsing and Canonicalization in jetty |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-03T21:40:12.093Z
Reserved: 2021-03-12T00:00:00
Link: CVE-2021-28164
No data.
Status : Modified
Published: 2021-04-01T15:15:14.157
Modified: 2024-11-21T05:59:13.460
Link: CVE-2021-28164
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA