Path Traversal Vulnerability in Eclipse Jetty by Eclipse Foundation
CVE-2021-28169
What is CVE-2021-28169?
Eclipse Jetty versions up to 9.4.40, 10.0.2, and 11.0.2 are susceptible to a path traversal vulnerability which allows attackers to craft requests with doubly encoded paths targeting the ConcatServlet. This leads to the exposure of sensitive resources within the WEB-INF directory, including critical configuration files such as web.xml. Attackers can exploit this flaw to gain insights into the application's structure and sensitive implementation details, posing significant risks to the security of the web application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Eclipse Jetty <= 9.4.40
Eclipse Jetty <= 10.0.2
Eclipse Jetty <= 11.0.2
References
EPSS Score
88% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
