For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jetty-securityUpgrade jetty-websocket-serverUpgrade jetty-javadocUpgrade jetty-websocket-parentUpgrade jetty-ioUpgrade jetty-jaasUpgrade jetty-plusUpgrade jetty-utilUpgrade jetty-jspc-maven-pluginUpgrade jetty-deployUpgrade jetty-servletUpgrade jetty-annotationsUpgrade jetty-websocket-commonUpgrade jetty-rewriteUpgrade jetty-proxyUpgrade jetty-antUpgrade jetty-websocket-clientUpgrade jetty-projectUpgrade jetty-jspUpgrade jetty-monitorUpgrade jetty-maven-pluginUpgrade jetty-clientUpgrade jetty-util-ajaxUpgrade jetty-websocket-servletUpgrade jetty-webappUpgrade jetty-servletsUpgrade jetty-xmlUpgrade jetty-websocket-apiUpgrade jetty-jaspiUpgrade jetty-continuationUpgrade jetty-serverUpgrade jetty-jmxUpgrade jetty-startUpgrade jetty-jndiUpgrade jetty-httpUpgrade jetty-runner | Jan 10, 2024 | Jun 9, 2021 |
| Debian | — | Upgrade jetty9 | Jun 21, 2021 | Jun 9, 2021 |
| Redhat Openshift | — | Upgrade jenkins | Oct 20, 2021 | Jun 8, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 9, 2021 |
| Suse | — | Upgrade jetty-servletUpgrade jetty-websocket-javadocUpgrade jetty-jmxUpgrade jetty-continuationUpgrade jetty-serverUpgrade jetty-jaasUpgrade jetty-openidUpgrade jetty-utilUpgrade jetty-javax-websocket-server-implUpgrade jetty-websocket-apiUpgrade jetty-util-ajaxUpgrade jetty-websocket-clientUpgrade jetty-proxyUpgrade jetty-minimal-javadocUpgrade jetty-jndiUpgrade jetty-webappUpgrade jetty-websocket-serverUpgrade jetty-jspUpgrade jetty-clientUpgrade jetty-ioUpgrade jetty-httpUpgrade jetty-securityUpgrade jetty-plusUpgrade jetty-javax-websocket-client-implUpgrade jetty-websocket-servletUpgrade jetty-xmlUpgrade jetty-annotationsUpgrade jetty-websocket-common | Jun 19, 2021 | Jun 9, 2021 |
| Ubuntu | — | No solution exists | Jul 1, 2025 | Jun 9, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub