This repository has been archived by the owner on Jun 16, 2023. It is now read-only.
CVE-2021-28169 (Medium) detected in multiple libraries #20
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2021-28169 - Medium Severity Vulnerability
Vulnerable Libraries - jetty-http-9.2.26.v20180806.jar, jetty-server-9.4.24.v20191120.jar, jetty-server-7.6.21.v20160908.jar, jetty-http-8.1.22.v20160922.jar, jetty-http-9.4.24.v20191120.jar, jetty-http-7.6.21.v20160908.jar, jetty-http-9.3.28.v20191105.jar, jetty-server-8.1.22.v20160922.jar, jetty-server-9.2.26.v20180806.jar, jetty-server-9.3.28.v20191105.jar
jetty-http-9.2.26.v20180806.jar
Administrative parent pom for Jetty modules
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.2.26.v20180806/2860272e69f7f09c5948ae1335f320c21a10eb29/jetty-http-9.2.26.v20180806.jar
Dependency Hierarchy:
jetty-server-9.4.24.v20191120.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.24.v20191120/7885cc3d5d7701a444acada7ab97f89846514875/jetty-server-9.4.24.v20191120.jar
Dependency Hierarchy:
jetty-server-7.6.21.v20160908.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/7.6.21.v20160908/a56288d7d1728f06fa01d0f5cd8394177ae249e0/jetty-server-7.6.21.v20160908.jar
Dependency Hierarchy:
jetty-http-8.1.22.v20160922.jar
Administrative parent pom for Jetty modules
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/8.1.22.v20160922/34350a9bf6955b75b00dda180d44109a2f5fc862/jetty-http-8.1.22.v20160922.jar
Dependency Hierarchy:
jetty-http-9.4.24.v20191120.jar
The Eclipse Jetty Project
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.24.v20191120/d3f0b0fb016ef8d35ffb199d928ffbcbfa121c86/jetty-http-9.4.24.v20191120.jar
Dependency Hierarchy:
jetty-http-7.6.21.v20160908.jar
Administrative parent pom for Jetty modules
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/7.6.21.v20160908/58dee82c3f15bbd1eeb60d59f02847b6efbd33f1/jetty-http-7.6.21.v20160908.jar
Dependency Hierarchy:
jetty-http-9.3.28.v20191105.jar
Administrative parent pom for Jetty modules
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.3.28.v20191105/17de21977bdcc406d69a63c36899c00d0ddcf991/jetty-http-9.3.28.v20191105.jar
Dependency Hierarchy:
jetty-server-8.1.22.v20160922.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/8.1.22.v20160922/713c1fefc16be4ee28aaa47261475173c9f98ba2/jetty-server-8.1.22.v20160922.jar
Dependency Hierarchy:
jetty-server-9.2.26.v20180806.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.2.26.v20180806/dc718537344846b0b5bb1e69bd27902c74a64568/jetty-server-9.2.26.v20180806.jar
Dependency Hierarchy:
jetty-server-9.3.28.v20191105.jar
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.3.28.v20191105/a07b200c91acafb6ecd9e3692b97c1e780d43c5/jetty-server-9.3.28.v20191105.jar
Dependency Hierarchy:
Found in HEAD commit: 4cb9afca7b4ab356e0863ec7515cb10a779ea02d
Found in base branch: master
Vulnerability Details
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to
/concat?/%2557EB-INF/web.xml
can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.Publish Date: 2021-06-09
URL: CVE-2021-28169
CVSS 3 Score Details (5.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-gwcr-j4wh-j3cq
Release Date: 2021-06-09
Fix Resolution (org.eclipse.jetty:jetty-http): 9.4.41.v20210516
Direct dependency fix Resolution (org.gretty:gretty-runner-jetty9): 3.0.6
Fix Resolution (org.eclipse.jetty:jetty-server): 9.4.41.v20210516
Direct dependency fix Resolution (org.gretty:gretty-runner-jetty9): 3.0.6
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: