← Back to browse · API

CVE-2021-34429

Severity
MEDIUM
CVSS
5.3
EPSS
0.99298
Risk score
55.95
CISA KEV
No
PoC
No
Published
2021-07-15
Modified
2024-08-04
First seen
2026-08-08
Aliases
EUVD-2021-1493, GHSA-VJV5-GP2W-65VM
Products
Eclipse Foundation:Eclipse Jetty 10.0.1 <unspecified, Eclipse Foundation:Eclipse Jetty 11.0.1 <unspecified, Eclipse Foundation:Eclipse Jetty 9.4.37 <unspecified, Eclipse Foundation:Eclipse Jetty unspecified ≤10.0.5, Eclipse Foundation:Eclipse Jetty unspecified ≤11.0.5, Eclipse Foundation:Eclipse Jetty unspecified ≤9.4.42
Sources
euvd EUVD-2021-1493

Description

For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.

References