5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
Affected (20)
Products: Eclipse: Jetty · Netapp: Cloud Manager, E Series Performance Analyzer, E Series Santricity Os Controller, E Series Santricity Web Services, Element Plug In For Vcenter Server, Santricity Cloud Connector, Snapcenter, Snapcenter Plug In, Storage Replication Adapter For Clustered Data Ontap, Vasa Provider For Clustered Data Ontap, Virtual Storage Console · Oracle: Autovue For Agile Product Lifecycle Management, Banking Apis, Banking Digital Experience, Communications Session Route Manager, Siebel Core Automation
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| From 11.0 to 11.70.1 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| From 9.6 | |
| From 9.6 | |
| From 9.6 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 21.0.2 | |
| Version 20.1 | |
| Version 20.1 | |
| From 8.0.0 to 8.2.4 | |
| Up to 21.9 |
Related CWEs
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-551
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
If a web server does not fully parse requested URLs before it examines them for authorization, it may be possible for an attacker to bypass authorization protection.
References (50)
Source: emo@eclipse.org
ExploitThird Party AdvisoryVDB Entry
Source: emo@eclipse.org
MitigationThird Party Advisory
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Not ApplicableThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.