Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Network
0

CVE-2021-34429

Disclosure Date: July 15, 2021
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
5.3 Medium
Impact Score:
1.4
Exploitability Score:
3.9
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
Low
Integrity (I):
None
Availability (A):
None

General Information

Vendors

  • eclipse,
  • netapp,
  • oracle

Products

  • autovue for agile product lifecycle management 21.0.2,
  • communications cloud native core binding support function 1.10.0,
  • communications cloud native core security edge protection proxy 1.5.0,
  • communications cloud native core service communication proxy 1.14.0,
  • communications cloud native core unified data repository 1.14.0,
  • communications diameter signaling router,
  • e-series santricity os controller,
  • e-series santricity web services -,
  • element plug-in for vcenter server -,
  • financial services crime and compliance management studio 8.0.8.2.0,
  • financial services crime and compliance management studio 8.0.8.3.0,
  • hci management node -,
  • jetty,
  • rest data services,
  • retail eftlink 20.0.1,
  • snap creator framework -,
  • snapcenter plug-in -,
  • solidfire -,
  • stream analytics,
  • stream analytics 19c

References

Advisory

Additional Info

Technical Analysis