For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jetty9 | Jul 30, 2024 | Jul 15, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 15, 2021 |
| Suse | — | Upgrade jetty-websocket-servletUpgrade jetty-xmlUpgrade jetty-websocket-commonUpgrade jetty-httpUpgrade jetty-jaasUpgrade jetty-securityUpgrade jetty-minimal-javadocUpgrade jetty-jspUpgrade jetty-webappUpgrade jetty-continuationUpgrade jetty-servletUpgrade jetty-serverUpgrade jetty-openidUpgrade jetty-util-ajaxUpgrade jetty-javax-websocket-server-implUpgrade jetty-javax-websocket-client-implUpgrade jetty-jmxUpgrade jetty-websocket-serverUpgrade jetty-websocket-clientUpgrade jetty-websocket-javadocUpgrade jetty-ioUpgrade jetty-jndiUpgrade jetty-websocket-apiUpgrade jetty-clientUpgrade jetty-annotationsUpgrade jetty-plusUpgrade jetty-proxyUpgrade jetty-util | Aug 26, 2021 | Jul 15, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 15, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub