CVE-2021-34429 is a medium-severity information disclosure vulnerability affecting Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5, and 11.0.1-11.0.5, as well as products from NetApp and Oracle utilizing these versions. Attackers can craft specific URIs with encoded characters to bypass security constraints and access the contents of the WEB-INF directory, potentially exposing sensitive information. The vulnerability has a CVSS score of 5.3, indicating a network-based attack with low complexity and no user interaction required, leading to a low impact on confidentiality. While not on the CISA KEV catalog, exploit intelligence shows available Metasploit modules, Nuclei templates, and an ExploitDB entry, indicating readily available exploit code. Despite this, there is no recorded community discussion or media coverage, which is typical for the majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.0.5CPE match | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
<= 11.0.5CPE match | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
<= 9.4.42CPE match | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 9.4.37, < 9.4.43CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 10.0.1, < 10.0.6CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.