5.3

CVE-2021-34429

Exploit

For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EclipseJetty Version >= 9.4.37 < 9.4.43
EclipseJetty Version >= 10.0.1 < 10.0.6
EclipseJetty Version >= 11.0.1 < 11.0.6
NetappE-series Santricity Os Controller Version >= 11.0 <= 11.70.1
NetappE-series Santricity Web Services Version- SwPlatformweb_services_proxy
NetappSnapcenter Plug-in Version- SwPlatformvmware_vsphere
NetappSolidfire Version-
OracleCommunications Diameter Signaling Router Version >= 8.0.0.0 <= 8.5.0.2
OracleRest Data Services SwEdition- Version < 22.1.1
OracleRetail Eftlink Version20.0.1
OracleStream Analytics Version < 19.1.0.0.6.4
OracleStream Analytics Version19c
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 93.8% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
emo@eclipse.org 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-551 Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

If a web server does not fully parse requested URLs before it examines them for authorization, it may be possible for an attacker to bypass authorization protection.