For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jetty-javadocUpgrade jetty-monitorUpgrade jetty-annotationsUpgrade jetty-websocket-commonUpgrade jetty-maven-pluginUpgrade jetty-securityUpgrade jetty-websocket-serverUpgrade jetty-websocket-clientUpgrade jetty-ioUpgrade jetty-antUpgrade jetty-jaasUpgrade jetty-servletUpgrade jetty-jspUpgrade jetty-proxyUpgrade jetty-plusUpgrade jetty-utilUpgrade jetty-projectUpgrade jetty-deployUpgrade jetty-rewriteUpgrade jetty-websocket-parentUpgrade jetty-clientUpgrade jetty-jspc-maven-pluginUpgrade jetty-jndiUpgrade jetty-startUpgrade jetty-runnerUpgrade jetty-continuationUpgrade jetty-serverUpgrade jetty-jmxUpgrade jetty-servletsUpgrade jetty-xmlUpgrade jetty-websocket-servletUpgrade jetty-jaspiUpgrade jetty-webappUpgrade jetty-util-ajaxUpgrade jetty-httpUpgrade jetty-websocket-api | Jan 10, 2024 | Jun 9, 2021 |
| Debian | — | Upgrade jetty9 | Jun 21, 2021 | Jun 9, 2021 |
| Redhat Openshift | — | Upgrade jenkins | Oct 20, 2021 | Jun 8, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 9, 2021 |
| Suse | — | Upgrade jetty-javax-websocket-client-implUpgrade jetty-ioUpgrade jetty-clientUpgrade jetty-securityUpgrade jetty-httpUpgrade jetty-jspUpgrade jetty-plusUpgrade jetty-websocket-serverUpgrade jetty-annotationsUpgrade jetty-websocket-commonUpgrade jetty-xmlUpgrade jetty-webappUpgrade jetty-websocket-servletUpgrade jetty-jmxUpgrade jetty-websocket-javadocUpgrade jetty-servletUpgrade jetty-openidUpgrade jetty-websocket-clientUpgrade jetty-util-ajaxUpgrade jetty-jndiUpgrade jetty-proxyUpgrade jetty-minimal-javadocUpgrade jetty-serverUpgrade jetty-jaasUpgrade jetty-utilUpgrade jetty-javax-websocket-server-implUpgrade jetty-websocket-apiUpgrade jetty-continuation | Jun 19, 2021 | Jun 9, 2021 |
| Ubuntu | — | No solution exists | Jul 1, 2025 | Jun 9, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub