In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "9.4.37-20210219"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.38-20210224"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-28164.json"
[
{
"events": [
{
"introduced": "11.0"
},
{
"last_affected": "11.70.1"
}
]
},
{
"events": [
{
"introduced": "9.6"
}
]
},
{
"events": [
{
"introduced": "9.6"
}
]
},
{
"events": [
{
"introduced": "9.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "21.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "20.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "21.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "20.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "21.1"
}
]
},
{
"events": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.2.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "21.9"
}
]
}
]