Description
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2688-1 | jetty9 security update |
Github GHSA |
GHSA-gwcr-j4wh-j3cq | Jetty Utility Servlets ConcatServlet Double Decoding Information Disclosure Vulnerability |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Eclipse
Subscribe
Jetty
Subscribe
Netapp
Subscribe
Active Iq Unified Manager
Subscribe
Hci
Subscribe
Management Services For Element Software
Subscribe
Snap Creator Framework
Subscribe
Oracle
Subscribe
Communications Cloud Native Core Policy
Subscribe
Rest Data Services
Subscribe
Redhat
Subscribe
Amq Broker
Subscribe
Amq Streams
Subscribe
Camel Quarkus
Subscribe
Integration
Subscribe
Jboss Fuse
Subscribe
Openshift
Subscribe
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-03T21:40:12.267Z
Reserved: 2021-03-12T00:00:00.000Z
Link: CVE-2021-28169
No data.
Status : Modified
Published: 2021-06-09T02:15:06.853
Modified: 2024-11-21T05:59:14.710
Link: CVE-2021-28169
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Github GHSA