← All CVEs

CVE-2021-28164

medium · 5.3

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

5.3
CVSS
82.4%
EPSS (exploit prob.)
100th
EPSS percentile
2021-04-01
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CWE-200CWE-551

Affected products

VendorProductAffected versions
eclipsejetty9.4.37
eclipsejetty9.4.38
netappcloud_managerall versions
netappe-series_performance_analyzerall versions
netappe-series_santricity_os_controller>= 11.0, <= 11.70.1
netappe-series_santricity_web_servicesall versions
netappelement_plug-in_for_vcenter_serverall versions
netappsantricity_cloud_connectorall versions
netappsnapcenterall versions
netappsnapcenter_plug-inall versions
netappstorage_replication_adapter_for_clustered_data_ontap>= 9.6
netappvasa_provider_for_clustered_data_ontap>= 9.6
netappvirtual_storage_console>= 9.6
oracleautovue_for_agile_product_lifecycle_management21.0.2
oraclebanking_apis20.1
oraclebanking_apis21.1
oraclebanking_digital_experience20.1
oraclebanking_digital_experience21.1
oraclecommunications_session_route_manager>= 8.0.0, <= 8.2.4
oraclesiebel_core_-_automation<= 21.9

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-28164