CVE-2021-28169: Infoleak
Eclipse Jetty could allow a remote attacker to obtain sensitive information, caused by a flaw in the ConcatServlet. By sending a specially-crafted request using a doubly encoded path, an attacker could exploit this vulnerability to obtain sensitive information from protected resources within the WEB-INF directory, and use this information to launch further attacks against the affected system.
Other sources
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to /concat?/%2557EB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-28169?
CVE-2021-28169 is a vulnerability in Eclipse Jetty versions <= 9.4.40 <= 10.0.2 <= 11.0.2 that allows a remote attacker to obtain sensitive information from protected resources within the web application.
What is the severity of CVE-2021-28169?
The severity of CVE-2021-28169 is medium, with a CVSS score of 5.3.
How can an attacker exploit CVE-2021-28169?
An attacker can exploit CVE-2021-28169 by sending a specially-crafted request using a doubly encoded path.
Which versions of Eclipse Jetty are affected by CVE-2021-28169?
Eclipse Jetty versions <= 9.4.40, <= 10.0.2, and <= 11.0.2 are affected by CVE-2021-28169.
How can I mitigate CVE-2021-28169?
To mitigate CVE-2021-28169, update Jetty to version 9.4.41, 10.0.3, or 11.0.3.