peter bassill · operator
$ cve CVE-2021-34429 JSON

CVE-2021-34429 EXPLOIT

5.3
MEDIUM · CVSS 3.1 · EPSS 99.3% (pctl 100)

Patch early

A public exploit exists.

Description

For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS99.3% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2021-07-15
Last modified2026-06-17

Affected (18)

VendorProduct
eclipsejetty
netappe-series santricity os controller
netappe-series santricity web services
netappelement plug-in for vcenter server
netapphci management node
netappsnap creator framework
netappsnapcenter plug-in
netappsolidfire
oracleautovue for agile product lifecycle management
oraclecommunications cloud native core binding support function
oraclecommunications cloud native core security edge protection proxy
oraclecommunications cloud native core service communication proxy
oraclecommunications cloud native core unified data repository
oraclecommunications diameter signaling router
oraclefinancial services crime and compliance management studio
oraclerest data services
oracleretail eftlink
oraclestream analytics

Public exploits

SourceTitleDate
exploit-dbEclipse Jetty 11.0.5 - Sensitive File Disclosure2021-11-03

References

→ the Explorer  ·  watch your stack  ·  NVD