S4E just found a low dns any record query
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-28169 Scanner

Detects 'Information Disclosure' vulnerability in Eclipse Jetty affects v. <= 9.4.40, <= 10.0.2, <= 11.0.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-28169
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Eclipse Jettyby The Eclipse Foundation
unspecified
Updated Aug 21, 2026View on NVD →
Detail

Eclipse Jetty is a popular Java-based web server and servlet container used for serving dynamic content. It is commonly used for embedded applications, web services, and small websites. Its lightweight and flexible nature offers a cost-effective solution to deploy Java-based applications. The software has garnered immense popularity for its strong support to the Servlet 3.1, JSP 2.3, WebSocket, OSGi, and JMX standards.

Recently, Eclipse Jetty has been identified with a severe vulnerability code named CVE-2021-28169. This vulnerability has been detected in versions 9.4.40, 10.0.2, and 11.0.2 of the Jetty software. The issue arises when a request is sent to the ConcatServlet with a doubly encoded path, leading to the exposure of sensitive information housed in the WEB-INF directory. An attacker can leverage this vulnerability to gain unauthorized access to confidential system files, retrieve sensitive information such as usernames, passwords, and other credentials, and even inject malicious code to the web application.

When exploited, the CVE-2021-28169 vulnerability allows an attacker to bypass authentication mechanisms, compromise user data, and take control of the web application. Since the WEB-INF folder contains critical files needed for the proper functioning of a web application, an attacker can steal data stored in the database, access configuration files, or execute arbitrary code on the server. The consequences can be catastrophic for companies, as they can suffer a significant loss of sensitive data, reputation, and revenue.

Thanks to the pro features offered by s4e.io, you can easily and quickly identify vulnerabilities in your digital assets. It offers automated scanning of web applications, technologies, and APIs and produces detailed reports of vulnerabilities and attack paths. This tool helps you stay ahead of the threat landscape and take proactive steps in securing your web applications. Consider investing in s4e.io to enhance your web application security posture and prevent the exploitation of critical vulnerabilities like CVE-2021-28169.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended to implement the following steps:

  • Upgrade your version of Eclipse Jetty to its latest version, since this vulnerability has been fixed in the latest version.
  • Ensure to validate user input data and prevent double encoding of URLs, which can lead to the exploitation of this vulnerability.
  • Implement access control mechanisms such as user authentication, authorization, and session management to safeguard against unauthorized access.
  • Regularly monitor and analyze system logs and behavior to detect any suspicious activity in real-time.
  • Deploy a robust security solution, such as a web application firewall or an intrusion detection system, to mitigate potential attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-28169 scanner - Information Disclosure vulnerability in Eclipse Jetty S4E