S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-28164 Scanner

Detects 'Information Disclosure' vulnerability in Eclipse Jetty affects v. from 9.4.37.v20210219 through 9.4.38.v20210224.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-28164
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Eclipse Jettyby The Eclipse Foundation
AFFECTED< unspecifiedSAFE ✓≥ unspecified
Updated Aug 21, 2026View on NVD →
Detail

Eclipse Jetty is an open-source Java-based HTTP web serving and servlet engine that is often used in embedded and standalone Java applications as well as in several popular web frameworks. With its lightweight and modular structure, Jetty is capable of running a diverse range of web-based applications including real-time services, event-driven applications, and RESTful web services.

Recently, the CVE-2021-28164 vulnerability was discovered in versions of Jetty ranging from 9.4.37.v20210219 to 9.4.38.v20210224. In technical terms, this flaw is related to the default compliance mode in which requests with URIs containing %2e or %2e%2e segments are allowed to access protected resources within the WEB-INF directory. This allows attackers to exploit the vulnerability and retrieve sensitive information pertaining to the web application's implementation without permission or authentication.

If exploited, this vulnerability can lead to severe consequences such as unauthorized access to sensitive data, vulnerable application code, and misuse of web application functionalities. Additionally, malicious actors can cause server crashes and manipulate and corrupt data, leading to potential reputational and financial damage to both individuals and organizations.

At s4e.io, customers can stay updated with the latest vulnerabilities and security threats through their pro features, which take into account each user's individual digital assets and provide ongoing assessment and analysis of potential risks. This feature allows customers to take proactive measures in safeguarding their digital assets and prevent malicious attacks such as the CVE-2021-28164 vulnerability.

 

REFERENCES

Solution Advice

To prevent such an attack, Jetty users are advised to follow certain best practices. These defence mechanisms include:

  • Upgrading their systems to the latest Jetty versions that do not contain the vulnerability.
  • Avoid using default compliance mode.
  • Disabling methods such as TRACE and DELETE on the server if they are not required for application functionality.
  • Implementing access control and authentication mechanisms to prevent unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-28164 scanner - Information Disclosure vulnerability in Eclipse Jetty | S4E