← All CVEs

CVE-2021-34429

medium · 5.3

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.

5.3
CVSS
99.3%
EPSS (exploit prob.)
100th
EPSS percentile
2021-07-15
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CWE-200CWE-551

Affected products

VendorProductAffected versions
eclipsejetty>= 9.4.37, < 9.4.43
eclipsejetty>= 10.0.1, < 10.0.6
eclipsejetty>= 11.0.1, < 11.0.6
netappe-series_santricity_os_controller>= 11.0, <= 11.70.1
netappe-series_santricity_web_servicesall versions
netappelement_plug-in_for_vcenter_serverall versions
netapphci_management_nodeall versions
netappsnap_creator_frameworkall versions
netappsnapcenter_plug-inall versions
netappsolidfireall versions
oracleautovue_for_agile_product_lifecycle_management21.0.2
oraclecommunications_cloud_native_core_binding_support_function1.10.0
oraclecommunications_cloud_native_core_security_edge_protection_proxy1.5.0
oraclecommunications_cloud_native_core_service_communication_proxy1.14.0
oraclecommunications_cloud_native_core_unified_data_repository1.14.0
oraclecommunications_diameter_signaling_router>= 8.0.0.0, <= 8.5.0.2
oraclefinancial_services_crime_and_compliance_management_studio8.0.8.2.0
oraclefinancial_services_crime_and_compliance_management_studio8.0.8.3.0
oraclerest_data_services< 22.1.1
oracleretail_eftlink20.0.1
oraclestream_analytics< 19.1.0.0.6.4
oraclestream_analytics19c

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-34429