In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
{ "binaries": [ { "binary_name": "libequinox-app-java", "binary_version": "1.3.600+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-bidi-java", "binary_version": "1.1.200+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-cm-java", "binary_version": "1.3.100+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-common-java", "binary_version": "3.10.100+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-concurrent-java", "binary_version": "1.1.200+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-console-java", "binary_version": "1.3.100+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-coordinator-java", "binary_version": "1.3.600+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-device-java", "binary_version": "1.0.700+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-ds-java", "binary_version": "1.5.200+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-event-java", "binary_version": "1.4.300+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-http-jetty-java", "binary_version": "3.6.100+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-http-jetty-starter-java", "binary_version": "1.1.100+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-http-registry-java", "binary_version": "1.1.600+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-http-servlet-java", "binary_version": "1.5.100+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-http-servletbridge-java", "binary_version": "1.1.100+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-io-java", "binary_version": "1.1.300+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-ip-java", "binary_version": "1.1.600+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-jsp-jasper-java", "binary_version": "1.1.100+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-jsp-jasper-registry-java", "binary_version": "1.1.100+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-metatype-java", "binary_version": "1.4.500+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-preferences-java", "binary_version": "3.7.200+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-region-java", "binary_version": "1.4.200+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-registry-java", "binary_version": "3.8.100+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-security-java", "binary_version": "1.2.500+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-servletbridge-java", "binary_version": "1.4.100+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-transforms-hook-java", "binary_version": "1.2.200+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-transforms-xslt-java", "binary_version": "1.0.500+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-useradmin-java", "binary_version": "1.1.600+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-util-java", "binary_version": "1.1.100+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-weaving-caching-java", "binary_version": "1.1.200+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-weaving-hook-java", "binary_version": "1.2.200+eclipse4.9-2~18.04" }, { "binary_name": "libequinox-wireadmin-java", "binary_version": "1.0.800+eclipse4.9-2~18.04" } ] }
{ "binaries": [ { "binary_name": "libequinox-app-java", "binary_version": "1.4.300+eclipse4.13-1" }, { "binary_name": "libequinox-bidi-java", "binary_version": "1.2.100+eclipse4.13-1" }, { "binary_name": "libequinox-cm-java", "binary_version": "1.4.100+eclipse4.13-1" }, { "binary_name": "libequinox-common-java", "binary_version": "3.10.500+eclipse4.13-1" }, { "binary_name": "libequinox-concurrent-java", "binary_version": "1.1.400+eclipse4.13-1" }, { "binary_name": "libequinox-console-java", "binary_version": "1.4.0+eclipse4.13-1" }, { "binary_name": "libequinox-coordinator-java", "binary_version": "1.3.600+eclipse4.13-1" }, { "binary_name": "libequinox-device-java", "binary_version": "1.0.800+eclipse4.13-1" }, { "binary_name": "libequinox-ds-java", "binary_version": "1.6.0+eclipse4.13-1" }, { "binary_name": "libequinox-event-java", "binary_version": "1.5.200+eclipse4.13-1" }, { "binary_name": "libequinox-http-jetty-java", "binary_version": "3.7.200+eclipse4.13-1" }, { "binary_name": "libequinox-http-jetty-starter-java", "binary_version": "1.1.100+eclipse4.13-1" }, { "binary_name": "libequinox-http-registry-java", "binary_version": "1.1.700+eclipse4.13-1" }, { "binary_name": "libequinox-http-servlet-java", "binary_version": "1.6.200+eclipse4.13-1" }, { "binary_name": "libequinox-http-servletbridge-java", "binary_version": "1.1.100+eclipse4.13-1" }, { "binary_name": "libequinox-io-java", "binary_version": "1.1.300+eclipse4.13-1" }, { "binary_name": "libequinox-ip-java", "binary_version": "1.1.600+eclipse4.13-1" }, { "binary_name": "libequinox-jsp-jasper-java", "binary_version": "1.1.300+eclipse4.13-1" }, { "binary_name": "libequinox-jsp-jasper-registry-java", "binary_version": "1.1.300+eclipse4.13-1" }, { "binary_name": "libequinox-metatype-java", "binary_version": "1.5.100+eclipse4.13-1" }, { "binary_name": "libequinox-preferences-java", "binary_version": "3.7.500+eclipse4.13-1" }, { "binary_name": "libequinox-region-java", "binary_version": "1.4.500+eclipse4.13-1" }, { "binary_name": "libequinox-registry-java", "binary_version": "3.8.500+eclipse4.13-1" }, { "binary_name": "libequinox-security-java", "binary_version": "1.3.300+eclipse4.13-1" }, { "binary_name": "libequinox-servletbridge-java", "binary_version": "1.5.100+eclipse4.13-1" }, { "binary_name": "libequinox-transforms-hook-java", "binary_version": "1.2.500+eclipse4.13-1" }, { "binary_name": "libequinox-transforms-xslt-java", "binary_version": "1.1.0+eclipse4.13-1" }, { "binary_name": "libequinox-useradmin-java", "binary_version": "1.1.700+eclipse4.13-1" }, { "binary_name": "libequinox-util-java", "binary_version": "1.1.300+eclipse4.13-1" }, { "binary_name": "libequinox-weaving-caching-java", "binary_version": "1.1.300+eclipse4.13-1" }, { "binary_name": "libequinox-weaving-hook-java", "binary_version": "1.2.400+eclipse4.13-1" }, { "binary_name": "libequinox-wireadmin-java", "binary_version": "1.0.800+eclipse4.13-1" } ] }
{ "binaries": [ { "binary_name": "libequinox-app-java", "binary_version": "1.5.100+eclipse4.19-1" }, { "binary_name": "libequinox-bidi-java", "binary_version": "1.3.100+eclipse4.19-1" }, { "binary_name": "libequinox-cm-java", "binary_version": "1.5.0+eclipse4.19-1" }, { "binary_name": "libequinox-common-java", "binary_version": "3.14.100+eclipse4.19-1" }, { "binary_name": "libequinox-concurrent-java", "binary_version": "1.2.0+eclipse4.19-1" }, { "binary_name": "libequinox-console-java", "binary_version": "1.4.300+eclipse4.19-1" }, { "binary_name": "libequinox-coordinator-java", "binary_version": "1.4.0+eclipse4.19-1" }, { "binary_name": "libequinox-device-java", "binary_version": "1.1.100+eclipse4.19-1" }, { "binary_name": "libequinox-event-java", "binary_version": "1.6.0+eclipse4.19-1" }, { "binary_name": "libequinox-http-jetty-java", "binary_version": "3.7.600+eclipse4.19-1" }, { "binary_name": "libequinox-http-jetty-starter-java", "binary_version": "1.1.100+eclipse4.19-1" }, { "binary_name": "libequinox-http-registry-java", "binary_version": "1.2.0+eclipse4.19-1" }, { "binary_name": "libequinox-http-servlet-java", "binary_version": "1.7.0+eclipse4.19-1" }, { "binary_name": "libequinox-http-servletbridge-java", "binary_version": "1.2.0+eclipse4.19-1" }, { "binary_name": "libequinox-io-java", "binary_version": "1.1.300+eclipse4.19-1" }, { "binary_name": "libequinox-ip-java", "binary_version": "1.1.600+eclipse4.19-1" }, { "binary_name": "libequinox-jsp-jasper-java", "binary_version": "1.1.500+eclipse4.19-1" }, { "binary_name": "libequinox-jsp-jasper-registry-java", "binary_version": "1.1.400+eclipse4.19-1" }, { "binary_name": "libequinox-metatype-java", "binary_version": "1.6.0+eclipse4.19-1" }, { "binary_name": "libequinox-preferences-java", "binary_version": "3.8.200+eclipse4.19-1" }, { "binary_name": "libequinox-region-java", "binary_version": "1.5.100+eclipse4.19-1" }, { "binary_name": "libequinox-registry-java", "binary_version": "3.10.100+eclipse4.19-1" }, { "binary_name": "libequinox-security-java", "binary_version": "1.3.600+eclipse4.19-1" }, { "binary_name": "libequinox-security-ui-java", "binary_version": "1.3.0+eclipse4.19-1" }, { "binary_name": "libequinox-servletbridge-java", "binary_version": "1.6.0+eclipse4.19-1" }, { "binary_name": "libequinox-transforms-hook-java", "binary_version": "1.3.0+eclipse4.19-1" }, { "binary_name": "libequinox-transforms-xslt-java", "binary_version": "1.2.0+eclipse4.19-1" }, { "binary_name": "libequinox-useradmin-java", "binary_version": "1.2.100+eclipse4.19-1" }, { "binary_name": "libequinox-util-java", "binary_version": "1.1.300+eclipse4.19-1" }, { "binary_name": "libequinox-weaving-caching-java", "binary_version": "1.2.0+eclipse4.19-1" }, { "binary_name": "libequinox-weaving-hook-java", "binary_version": "1.3.0+eclipse4.19-1" }, { "binary_name": "libequinox-wireadmin-java", "binary_version": "1.0.800+eclipse4.19-1" } ] }