cbcvebase.
CVE-2021-34429
published 2021-07-15

CVE-2021-34429: For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF…

medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EXPLOIT
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianjetty9< jetty9 9.4.39-3 (bookworm)jetty9 9.4.39-3 (bookworm)
eclipsejetty>= 10.0.1 < 10.0.610.0.6
eclipsejetty>= 11.0.1 < 11.0.611.0.6
eclipsejetty>= 9.4.37 < 9.4.439.4.43
netappe-series_santricity_os_controller11.0 – 11.70.1
oracleautovue_for_agile_product_lifecycle_management
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_cloud_native_core_security_edge_protection_proxy
oraclecommunications_cloud_native_core_service_communication_proxy
oraclecommunications_cloud_native_core_unified_data_repository
oraclecommunications_diameter_signaling_router8.0.0.0 – 8.5.0.2
oraclefinancial_services_crime_and_compliance_management_studio
oraclefinancial_services_crime_and_compliance_management_studio
oraclerest_data_services< 22.1.122.1.1
oracleretail_eftlink
oraclestream_analytics< 19.1.0.0.6.419.1.0.0.6.4
oraclestream_analytics

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ghsa5.3MEDIUM
osv5.3MEDIUM
vulncheck5.3MEDIUM