CVE-2021-28164 is an information disclosure vulnerability in Eclipse Jetty versions 9.4.37.v20210219 to 9.4.38.v20210224, also affecting NetApp and Oracle products. It allows unauthenticated attackers to access sensitive files within the WEB-INF directory by manipulating URIs with encoded directory traversal sequences. This medium-severity vulnerability (CVSS 5.3) has a low attack complexity and can lead to the exposure of confidential web application implementation details. While not listed on the KEV catalog, exploit intelligence indicates readily available exploit modules for Metasploit and Nuclei, along with an ExploitDB entry, suggesting a high potential for exploitation. Community discussion and media coverage are present, further highlighting its relevance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.4.37CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:9.4.37:20210219:*:*:*:*:*:* | ||
9.4.38CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:9.4.38:20210224:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:cloud_manager:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:* | ||
>= 11.0, <= 11.70.1CPE matchmatch criteria | cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.