SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-34429

For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints.

MEDIUM 5.3EPSS 99.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 99.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
99.30% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-551
Affected
eclipse/jetty · netapp/e-series santricity os controller · netapp/e-series santricity web services · netapp/element plug-in for vcenter server · netapp/hci management node · netapp/snap creator framework · netapp/snapcenter plug-in · netapp/solidfire · oracle/autovue for agile product lifecycle management · oracle/communications cloud native core binding support function · oracle/communications cloud native core security edge protection proxy · oracle/communications cloud native core service communication proxy · oracle/communications cloud native core unified data repository · oracle/communications diameter signaling router · oracle/financial services crime and compliance management studio · oracle/rest data services · oracle/retail eftlink · oracle/stream analytics
Source
emo@eclipse.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.