CVE-2021-28169 is an information disclosure vulnerability affecting Eclipse Jetty versions 9.4.40 and earlier, 10.0.2 and earlier, and 11.0.2 and earlier, as well as products from Debian, Eclipse, NetApp, and Oracle. An unauthenticated attacker can exploit this flaw by sending a specially crafted, doubly encoded request to the ConcatServlet, allowing access to sensitive files within the WEB-INF directory, such as web.xml. This vulnerability has a CVSS score of 5.3 (Medium), indicating a low attack complexity and no user interaction required, with the primary impact being the potential exposure of confidential information. While not listed on the KEV catalog, its high EPSS and FAUCET Risk Score suggest a significant likelihood of exploitation, and Nuclei templates exist for detection, though no Metasploit or ExploitDB modules are publicly available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.0.2CPE match | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
<= 11.0.2CPE match | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
<= 9.4.40CPE match | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
< 9.4.41CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.0.3CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.