CVE-2021-34429

For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
eclipseCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
eclipsejetty
9.4.37 ≤
𝑥
< 9.4.43
eclipsejetty
10.0.1 ≤
𝑥
< 10.0.6
eclipsejetty
11.0.1 ≤
𝑥
< 11.0.6
netappe-series_santricity_os_controller
11.0 ≤
𝑥
≤ 11.70.1
netappe-series_santricity_web_services
-
netappelement_plug-in_for_vcenter_server
-
netapphci_management_node
-
netappsnap_creator_framework
-
netappsnapcenter_plug-in
-
netappsolidfire
-
oracleautovue_for_agile_product_lifecycle_management
21.0.2
oraclecommunications_cloud_native_core_binding_support_function
1.10.0
oraclecommunications_cloud_native_core_security_edge_protection_proxy
1.5.0
oraclecommunications_cloud_native_core_service_communication_proxy
1.14.0
oraclecommunications_cloud_native_core_unified_data_repository
1.14.0
oraclecommunications_diameter_signaling_router
8.0.0.0 ≤
𝑥
≤ 8.5.0.2
oraclefinancial_services_crime_and_compliance_management_studio
8.0.8.2.0
oraclefinancial_services_crime_and_compliance_management_studio
8.0.8.3.0
oraclerest_data_services
𝑥
< 22.1.1
oracleretail_eftlink
20.0.1
oraclestream_analytics
𝑥
< 19.1.0.0.6.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jetty9
bullseye (security)
9.4.50-4+deb11u2
fixed
bullseye
9.4.50-4+deb11u2
fixed
buster
not-affected
stretch
not-affected
bookworm
9.4.50-4+deb12u3
fixed
bookworm (security)
9.4.50-4+deb12u3
fixed
sid
9.4.56-1
fixed
trixie
9.4.56-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jetty9
noble
needed
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needed
impish
ignored
hirsute
ignored
groovy
not-affected
focal
not-affected
bionic
not-affected
xenial
needs-triage
trusty
dne
References