Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-28164

86
FAUCET Score

CVE-2021-28164 is an information disclosure vulnerability in Eclipse Jetty versions 9.4.37.v20210219 to 9.4.38.v20210224, also affecting NetApp and Oracle products. It allows unauthenticated attackers to access sensitive files within the WEB-INF directory by manipulating URIs with encoded directory traversal sequences. This medium-severity vulnerability (CVSS 5.3) has a low attack complexity and can lead to the exposure of confidential web application implementation details. While not listed on the KEV catalog, exploit intelligence indicates readily available exploit modules for Metasploit and Nuclei, along with an ExploitDB entry, suggesting a high potential for exploitation. Community discussion and media coverage are present, further highlighting its relevance.

Impacted Technologies

VendorProductVersion(s)CPE
9.4.37CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:9.4.37:20210219:*:*:*:*:*:*
9.4.38CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:9.4.38:20210224:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:cloud_manager:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*
>= 11.0, <= 11.70.1CPE matchmatch criteria
cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
82.37%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: Jetty WEB-INF File Disclosure · Jul 15, 2021
Nuclei: CVE-2021-28164 · Jun 9, 2021
ExploitDB: EDB-50438 · Oct 22, 2021
This CVE's current EPSS score of 0.8237 is in the 100th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (15)

mavenpatch availablevia ghsa
Product: org.eclipse.jetty:jetty-webappFixed in: 9.4.39
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ 7.9.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Streams 1.6.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Streams 1.8.0Fixed in: jetty-server
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Developer ToolsFixed in: rh-eclipse-jetty-0:9.4.40-1.1.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.10Fixed in: jetty
View patch
redhatpatch availablevia redhat_api
Product: RHAF Camel-K 1.8Fixed in: jetty
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Integration Camel Quarkus 2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ 7.8.2Fixed in: jetty-server
View patch
github_advisoryworkaround availablevia nvd_reference
View patch
redhatno patchvia redhat_api
Product: Red Hat Integration Camel Quarkus 1Fixed in: jetty
redhatno patchvia redhat_api
Product: Red Hat Integration Service RegistryFixed in: jetty-server
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: eclipse:rhel8/jetty
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: opendaylight

Vendor Advisories (2)

mavenGHSA-v7ff-8wcx-gmc5medium

Authorization Before Parsing and Canonicalization in jetty

Apr 6, 2021
redhatCVE-2021-28164Moderate

jetty: Ambiguous paths can access WEB-INF

Apr 1, 2021

References

packetstormsecurity.com / files/164590/Jetty-9.4.37.v20210219-Information-Disclosure.html
ExploitThird Party AdvisoryVDB Entry
github.com / eclipse/jetty.project/security/advisories/GHSA-v7ff-8wcx-gmc5
MitigationThird Party Advisory
lists.apache.org / thread.html/r0841b06b48324cfc81325de3c05a92e53f997185f9d71ff47734d961%40%3Cissues.solr.apache.org%3E
lists.apache.org / thread.html/r111f1ce28b133a8090ca4f809a1bdf18a777426fc058dc3a16c39c66%40%3Cissues.solr.apache.org%3E
lists.apache.org / thread.html/r2a3ea27cca2ac7352d392b023b72e824387bc9ff16ba245ec663bdc6%40%3Cissues.zookeeper.apache.org%3E
lists.apache.org / thread.html/r2ea2f0541121f17e470a0184843720046c59d4bde6d42bf5ca6fad81%40%3Cissues.solr.apache.org%3E
lists.apache.org / thread.html/r3c55b0baa4dc38958ae147b2f216e212605f1071297f845e14477d36%40%3Cissues.zookeeper.apache.org%3E
lists.apache.org / thread.html/r4a66bfbf62281e31bc1345ebecbfd96f35199eecd77bfe4e903e906f%40%3Cissues.ignite.apache.org%3E
lists.apache.org / thread.html/r4b1fef117bccc7f5fd4c45fd2cabc26838df823fe5ca94bc42a4fd46%40%3Cissues.ignite.apache.org%3E
lists.apache.org / thread.html/r5b3693da7ecb8a75c0e930b4ca26a5f97aa0207d9dae4aa8cc65fe6b%40%3Cissues.ignite.apache.org%3E
lists.apache.org / thread.html/r6ac9e263129328c0db9940d72b4a6062e703c58918dd34bd22cdf8dd%40%3Cissues.ignite.apache.org%3E
lists.apache.org / thread.html/r763840320a80e515331cbc1e613fa93f25faf62e991974171a325c82%40%3Cdev.zookeeper.apache.org%3E
lists.apache.org / thread.html/r780c3c210a05c5bf7b4671303f46afc3fe56758e92864e1a5f0590d0%40%3Cjira.kafka.apache.org%3E
lists.apache.org / thread.html/r7dd079fa0ac6f47ba1ad0af98d7d0276547b8a4e005f034fb1016951%40%3Cissues.zookeeper.apache.org%3E
lists.apache.org / thread.html/r8e6c116628c1277c3cf132012a66c46a0863fa2a3037c0707d4640d4%40%3Cissues.zookeeper.apache.org%3E
lists.apache.org / thread.html/r90e7b4c42a96d74c219e448bee6a329ab0cd3205c44b63471d96c3ab%40%3Cissues.zookeeper.apache.org%3E
lists.apache.org / thread.html/r9974f64723875052e02787b2a5eda689ac5247c71b827d455e5dc9a6%40%3Cissues.solr.apache.org%3E
lists.apache.org / thread.html/rbc075a4ac85e7a8e47420b7383f16ffa0af3b792b8423584735f369f%40%3Cissues.solr.apache.org%3E
lists.apache.org / thread.html/rcea249eb7a0d243f21696e4985de33f3780399bf7b31ea1f6d489b8b%40%3Cissues.zookeeper.apache.org%3E
lists.apache.org / thread.html/rd0471252aeb3384c3cfa6d131374646d4641b80dd313e7b476c47a9c%40%3Cissues.solr.apache.org%3E
lists.apache.org / thread.html/rd7c8fb305a8637480dc943ba08424c8992dccad018cd1405eb2afe0e%40%3Cdev.ignite.apache.org%3E
security.netapp.com / advisory/ntap-20210611-0006
Third Party Advisory
oracle.com / security-alerts/cpuapr2022.html
Not ApplicableThird Party Advisory
oracle.com / security-alerts/cpujan2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuoct2021.html
PatchThird Party Advisory