Vulnerability record · CVE-2021-28164 · published 1 April 2021
CVE-2021-28164: Eclipse Jetty URI normalization flaw exposes WEB-INF files
Eclipse · Jetty
Eclipse Jetty 9.4.37.v20210219 through 9.4.38.v20210224 in default compliance mode accepts request URIs containing %2e or %2e%2e segments, letting them reach protected resources under WEB-INF. A request such as /context/%2e/WEB-INF/web.xml can return web.xml, exposing implementation details of the web application. The flaw is an information disclosure issue, not code execution.
Description
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Automated analysis
high priorityThe flaw is trivially reachable without authentication and has very high EPSS with public exploit code, though it only discloses files rather than enabling code execution.
What it is
Eclipse Jetty 9.4.37.v20210219 through 9.4.38.v20210224 in default compliance mode accepts request URIs containing %2e or %2e%2e segments, letting them reach protected resources under WEB-INF. A request such as /context/%2e/WEB-INF/web.xml can return web.xml, exposing implementation details of the web application. The flaw is an information disclosure issue, not code execution.
Impact
An unauthenticated remote attacker can read files inside WEB-INF, such as web.xml, gaining configuration and implementation details that aid further attacks. The direct impact is limited to confidentiality of those files.
Attack surface
Reachable over the network via a crafted HTTP request to a Jetty-hosted context; the CVSS vector shows no privileges and no user interaction required. Any exposed Jetty instance running an affected version in default compliance mode is in scope.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.824, 99.6th percentile) and a public Packet Storm exploit reference exists, indicating active interest and available proof-of-concept code. No ransomware association is documented.
What to do
- Upgrade Eclipse Jetty to a version after 9.4.38.v20210224 that contains the fix; apply vendor patches for bundled Jetty in NetApp and Oracle products.
- If immediate upgrade is not possible, follow the Jetty security advisory GHSA-v7ff-8wcx-gmc5 mitigation guidance, including enabling a stricter compliance mode.
- Block or normalize request URIs containing encoded dot segments (%2e, %2e%2e) at the reverse proxy or WAF before they reach Jetty.
- Restrict network access to Jetty management and application contexts to trusted sources only.
- Inventory all products embedding Jetty (NetApp, Oracle, Apache projects) and track their vendor advisories for patched builds.
Detection
- Search web access logs for requests containing %2e or %2e%2e in the URI path, especially targeting /WEB-INF/.
- Alert on HTTP responses returning web.xml or other WEB-INF content with 200 status.
- Monitor for encoded traversal patterns in proxy, WAF and load balancer logs.
- Correlate Jetty version banners or server headers with known affected 9.4.37/9.4.38 builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-28164 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-28164), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.