CVE-2021-34429
15.07.2021, 17:15
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.Enginsight
Vendor | Product | Version |
---|---|---|
eclipse | jetty | 9.4.37 ≤ 𝑥 < 9.4.43 |
eclipse | jetty | 10.0.1 ≤ 𝑥 < 10.0.6 |
eclipse | jetty | 11.0.1 ≤ 𝑥 < 11.0.6 |
netapp | e-series_santricity_os_controller | 11.0 ≤ 𝑥 ≤ 11.70.1 |
netapp | e-series_santricity_web_services | - |
netapp | element_plug-in_for_vcenter_server | - |
netapp | hci_management_node | - |
netapp | snap_creator_framework | - |
netapp | snapcenter_plug-in | - |
netapp | solidfire | - |
oracle | autovue_for_agile_product_lifecycle_management | 21.0.2 |
oracle | communications_cloud_native_core_binding_support_function | 1.10.0 |
oracle | communications_cloud_native_core_security_edge_protection_proxy | 1.5.0 |
oracle | communications_cloud_native_core_service_communication_proxy | 1.14.0 |
oracle | communications_cloud_native_core_unified_data_repository | 1.14.0 |
oracle | communications_diameter_signaling_router | 8.0.0.0 ≤ 𝑥 ≤ 8.5.0.2 |
oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.2.0 |
oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.3.0 |
oracle | rest_data_services | 𝑥 < 22.1.1 |
oracle | retail_eftlink | 20.0.1 |
oracle | stream_analytics | 𝑥 < 19.1.0.0.6.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References