vendor:
Jetty
by:
Mayank Deshmukh
8.8
CVSS
HIGH
Sensitive File Disclosure
284
CWE
Product Name: Jetty
Affected Version From: 9.4.37
Affected Version To: 9.4.43, 10.0.1, 10.0.6, 11.0.1, 11.0.6
Patch Exists: YES
Related CWE: CVE-2021-34429
CPE: a:eclipse:jetty
Tags: cve,cve2021,jetty
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Nuclei References:
https://github.com/eclipse/jetty.project/security/advisories/GHSA-vjv5-gp2w-65vm, https://lists.apache.org/thread.html/r763840320a80e515331cbc1e613fa93f25faf62e991974171a325c82@dev.zookeeper.apache.org, https://lists.apache.org/thread.html/r7dd079fa0ac6f47ba1ad0af98d7d0276547b8a4e005f034fb1016951@issues.zookeeper.apache.org, https://nvd.nist.gov/vuln/detail/CVE-2021-34429, https://lists.apache.org/thread.html/r029c0c6833c8bb6acb094733fd7b75029d633f47a92f1c9d14391fc0@notifications.zookeeper.apache.org
Nuclei Metadata: {'max-request': 2, 'vendor': 'eclipse', 'product': 'jetty'}
Platforms Tested: Kali Linux
2021
Eclipse Jetty 11.0.5 – Sensitive File Disclosure
A vulnerability in Eclipse Jetty could allow an unauthenticated, remote attacker to gain access to sensitive information on a targeted system. The vulnerability is due to improper access control of certain files. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted system. A successful exploit could allow the attacker to gain access to sensitive information, such as web.xml file.
Mitigation:
Upgrade to the latest version of Eclipse Jetty.