Element Plug In For Vcenter Server
Vendor:
First CVE: Apr 29, 2019 · Active for 7 years
9
Total CVEs
More Total CVEs than 88% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Element Plug In For Vcenter Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 29, 2019
7 years ago
Most Recent CVE
Jul 7, 2022
1,481 days ago
CVE Severity & Scoring
Element Plug In For Vcenter Server9 CVEs
33%
33%
22%
11%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical1 (11.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High2 (22.2%)
None7 (77.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34429MEDIUM For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or byp | Jul 15, 2021 | 5.3 | 91 | NO | YES |
CVE-2021-28164MEDIUM In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources withi | Apr 1, 2021 | 5.3 | 86 | NO | YES |
CVE-2020-27223MEDIUM In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality | Feb 26, 2021 | 5.3 | 61 | NO | NO |
CVE-2021-26987CRITICAL Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploi | Mar 15, 2021 | 9.8 | 30 | NO | NO |
CVE-2022-2048HIGH In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connec | Jul 7, 2022 | 7.5 | 24 | NO | NO |
CVE-2019-5492HIGH Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthenticated attacker. NetApp HCI Compute Node versions prior to 1.4P | Apr 29, 2019 | 7.5 | 24 | NO | NO |
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in | Jun 22, 2021 | 3.5 | 18 | NO | NO |
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory i | Apr 1, 2021 | 2.7 | 17 | NO | NO |
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI | Jul 7, 2022 | 2.7 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
22.2% of CVEs· 98th percentile
Nuclei
2 CVEs
22.2% of CVEs· 98th percentile
ExploitDB
2 CVEs
22.2% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Element Plug In For Vcenter Server
Top CWEs
Versions
No cataloged versions.