CVE detail
CVE-2021-28169 — CVE-2021-28169
Published 2021-06-09 · Modified 2026-06-17 · Vendor eclipse · Product jetty · Source nvd
MEDIUM
severity
CVSS-derived band
0.7848
EPSS probability
exploitation probability, 30d
100.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References