Detects 'Information Disclosure' vulnerability in Eclipse Jetty affects v. from 9.4.37.v20210219 through 9.4.38.v20210224.


Eclipse Jetty is an open-source Java-based HTTP web serving and servlet engine that is often used in embedded and standalone Java applications as well as in several popular web frameworks. With its lightweight and modular structure, Jetty is capable of running a diverse range of web-based applications including real-time services, event-driven applications, and RESTful web services.

Recently, the CVE-2021-28164 vulnerability was discovered in versions of Jetty ranging from 9.4.37.v20210219 to 9.4.38.v20210224. In technical terms, this flaw is related to the default compliance mode in which requests with URIs containing %2e or %2e%2e segments are allowed to access protected resources within the WEB-INF directory. This allows attackers to exploit the vulnerability and retrieve sensitive information pertaining to the web application's implementation without permission or authentication.

If exploited, this vulnerability can lead to severe consequences such as unauthorized access to sensitive data, vulnerable application code, and misuse of web application functionalities. Additionally, malicious actors can cause server crashes and manipulate and corrupt data, leading to potential reputational and financial damage to both individuals and organizations.

