摘要:
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
安全等级: Low
公告ID: KylinSec-SA-2024-1604
发布日期: 2024年5月27日
关联CVE: CVE-2021-28164
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2021-28164 | KY3.4-4A | jetty | Unaffected |
CVE-2021-28164 | KY3.4-5 | jetty | Unaffected |
CVE-2021-28164 | KY3.5.1 | jetty | Unaffected |
CVE-2021-28164 | KY3.5.2 | jetty | Unaffected |