← Vulnerability feed

Vulnerability record · CVE-2021-28164 · published 1 April 2021

CVE-2021-28164: Eclipse Jetty URI normalization flaw exposes WEB-INF files

Eclipse · Jetty

Eclipse Jetty 9.4.37.v20210219 through 9.4.38.v20210224 in default compliance mode accepts request URIs containing %2e or %2e%2e segments, letting them reach protected resources under WEB-INF. A request such as /context/%2e/WEB-INF/web.xml can return web.xml, exposing implementation details of the web application. The flaw is an information disclosure issue, not code execution.

5.3 CVSS 3.1 Medium EPSS 82% · top 0.3% CWE-200 · Information exposureCWE-551 · CWE-551
5.3CVSS 3.1 base score, v2 5.0
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
17Affected product versions listed by NVD
50References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw is trivially reachable without authentication and has very high EPSS with public exploit code, though it only discloses files rather than enabling code execution.

What it is

Eclipse Jetty 9.4.37.v20210219 through 9.4.38.v20210224 in default compliance mode accepts request URIs containing %2e or %2e%2e segments, letting them reach protected resources under WEB-INF. A request such as /context/%2e/WEB-INF/web.xml can return web.xml, exposing implementation details of the web application. The flaw is an information disclosure issue, not code execution.

Impact

An unauthenticated remote attacker can read files inside WEB-INF, such as web.xml, gaining configuration and implementation details that aid further attacks. The direct impact is limited to confidentiality of those files.

Attack surface

Reachable over the network via a crafted HTTP request to a Jetty-hosted context; the CVSS vector shows no privileges and no user interaction required. Any exposed Jetty instance running an affected version in default compliance mode is in scope.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.824, 99.6th percentile) and a public Packet Storm exploit reference exists, indicating active interest and available proof-of-concept code. No ransomware association is documented.

What to do

  • Upgrade Eclipse Jetty to a version after 9.4.38.v20210224 that contains the fix; apply vendor patches for bundled Jetty in NetApp and Oracle products.
  • If immediate upgrade is not possible, follow the Jetty security advisory GHSA-v7ff-8wcx-gmc5 mitigation guidance, including enabling a stricter compliance mode.
  • Block or normalize request URIs containing encoded dot segments (%2e, %2e%2e) at the reverse proxy or WAF before they reach Jetty.
  • Restrict network access to Jetty management and application contexts to trusted sources only.
  • Inventory all products embedding Jetty (NetApp, Oracle, Apache projects) and track their vendor advisories for patched builds.

Detection

  • Search web access logs for requests containing %2e or %2e%2e in the URI path, especially targeting /WEB-INF/.
  • Alert on HTTP responses returning web.xml or other WEB-INF content with 200 status.
  • Monitor for encoded traversal patterns in proxy, WAF and load balancer logs.
  • Correlate Jetty version banners or server headers with known affected 9.4.37/9.4.38 builds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/164590/Jetty-9.4.37.v20210219-Information-Disclosure.html ExploitThird Party AdvisoryVDB Entry
https://github.com/eclipse/jetty.project/security/advisories/GHSA-v7ff-8wcx-gmc5 MitigationThird Party Advisory
https://lists.apache.org/thread.html/r0841b06b48324cfc81325de3c05a92e53f997185f9d71ff47734d961%40%3Cissues.solr.apache.o
https://lists.apache.org/thread.html/r111f1ce28b133a8090ca4f809a1bdf18a777426fc058dc3a16c39c66%40%3Cissues.solr.apache.o
https://lists.apache.org/thread.html/r2a3ea27cca2ac7352d392b023b72e824387bc9ff16ba245ec663bdc6%40%3Cissues.zookeeper.apa
https://lists.apache.org/thread.html/r2ea2f0541121f17e470a0184843720046c59d4bde6d42bf5ca6fad81%40%3Cissues.solr.apache.o
https://lists.apache.org/thread.html/r3c55b0baa4dc38958ae147b2f216e212605f1071297f845e14477d36%40%3Cissues.zookeeper.apa
https://lists.apache.org/thread.html/r4a66bfbf62281e31bc1345ebecbfd96f35199eecd77bfe4e903e906f%40%3Cissues.ignite.apache
https://lists.apache.org/thread.html/r4b1fef117bccc7f5fd4c45fd2cabc26838df823fe5ca94bc42a4fd46%40%3Cissues.ignite.apache
https://lists.apache.org/thread.html/r5b3693da7ecb8a75c0e930b4ca26a5f97aa0207d9dae4aa8cc65fe6b%40%3Cissues.ignite.apache
https://lists.apache.org/thread.html/r6ac9e263129328c0db9940d72b4a6062e703c58918dd34bd22cdf8dd%40%3Cissues.ignite.apache
https://lists.apache.org/thread.html/r763840320a80e515331cbc1e613fa93f25faf62e991974171a325c82%40%3Cdev.zookeeper.apache
https://lists.apache.org/thread.html/r780c3c210a05c5bf7b4671303f46afc3fe56758e92864e1a5f0590d0%40%3Cjira.kafka.apache.or
https://lists.apache.org/thread.html/r7dd079fa0ac6f47ba1ad0af98d7d0276547b8a4e005f034fb1016951%40%3Cissues.zookeeper.apa
https://lists.apache.org/thread.html/r8e6c116628c1277c3cf132012a66c46a0863fa2a3037c0707d4640d4%40%3Cissues.zookeeper.apa
https://lists.apache.org/thread.html/r90e7b4c42a96d74c219e448bee6a329ab0cd3205c44b63471d96c3ab%40%3Cissues.zookeeper.apa
https://lists.apache.org/thread.html/r9974f64723875052e02787b2a5eda689ac5247c71b827d455e5dc9a6%40%3Cissues.solr.apache.o
https://lists.apache.org/thread.html/rbc075a4ac85e7a8e47420b7383f16ffa0af3b792b8423584735f369f%40%3Cissues.solr.apache.o
https://lists.apache.org/thread.html/rcea249eb7a0d243f21696e4985de33f3780399bf7b31ea1f6d489b8b%40%3Cissues.zookeeper.apa
https://lists.apache.org/thread.html/rd0471252aeb3384c3cfa6d131374646d4641b80dd313e7b476c47a9c%40%3Cissues.solr.apache.o
https://lists.apache.org/thread.html/rd7c8fb305a8637480dc943ba08424c8992dccad018cd1405eb2afe0e%40%3Cdev.ignite.apache.or
https://security.netapp.com/advisory/ntap-20210611-0006/ Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Not ApplicableThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
http://packetstormsecurity.com/files/164590/Jetty-9.4.37.v20210219-Information-Disclosure.html ExploitThird Party AdvisoryVDB Entry
https://github.com/eclipse/jetty.project/security/advisories/GHSA-v7ff-8wcx-gmc5 MitigationThird Party Advisory
https://lists.apache.org/thread.html/r0841b06b48324cfc81325de3c05a92e53f997185f9d71ff47734d961%40%3Cissues.solr.apache.o
https://lists.apache.org/thread.html/r111f1ce28b133a8090ca4f809a1bdf18a777426fc058dc3a16c39c66%40%3Cissues.solr.apache.o
https://lists.apache.org/thread.html/r2a3ea27cca2ac7352d392b023b72e824387bc9ff16ba245ec663bdc6%40%3Cissues.zookeeper.apa
https://lists.apache.org/thread.html/r2ea2f0541121f17e470a0184843720046c59d4bde6d42bf5ca6fad81%40%3Cissues.solr.apache.o
https://lists.apache.org/thread.html/r3c55b0baa4dc38958ae147b2f216e212605f1071297f845e14477d36%40%3Cissues.zookeeper.apa
https://lists.apache.org/thread.html/r4a66bfbf62281e31bc1345ebecbfd96f35199eecd77bfe4e903e906f%40%3Cissues.ignite.apache
https://lists.apache.org/thread.html/r4b1fef117bccc7f5fd4c45fd2cabc26838df823fe5ca94bc42a4fd46%40%3Cissues.ignite.apache
https://lists.apache.org/thread.html/r5b3693da7ecb8a75c0e930b4ca26a5f97aa0207d9dae4aa8cc65fe6b%40%3Cissues.ignite.apache
https://lists.apache.org/thread.html/r6ac9e263129328c0db9940d72b4a6062e703c58918dd34bd22cdf8dd%40%3Cissues.ignite.apache
https://lists.apache.org/thread.html/r763840320a80e515331cbc1e613fa93f25faf62e991974171a325c82%40%3Cdev.zookeeper.apache
https://lists.apache.org/thread.html/r780c3c210a05c5bf7b4671303f46afc3fe56758e92864e1a5f0590d0%40%3Cjira.kafka.apache.or
https://lists.apache.org/thread.html/r7dd079fa0ac6f47ba1ad0af98d7d0276547b8a4e005f034fb1016951%40%3Cissues.zookeeper.apa
https://lists.apache.org/thread.html/r8e6c116628c1277c3cf132012a66c46a0863fa2a3037c0707d4640d4%40%3Cissues.zookeeper.apa

Track CVE-2021-28164 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed7.8CVE-2019-13272Linux kernel ptrace credential mishandling allows local root escalationThe Linux kernel before 5.1.17 mishandles credential recording in ptrace_link (kernel/ptrace.c) when a process creates a ptrace relationship, and als…KEVEPSS 52%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2021-43527Mozilla nss out-of-bounds write vulnerabilityNSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signa…EPSS 18%9.8CVE-2021-3711OpenSSL SM2 decryption buffer overflowOpenSSL's SM2 decryption code miscalculates the output buffer size needed by EVP_PKEY_decrypt(), so the first sizing call can return a value smaller …EPSS 88%analysed9.8CVE-2021-26707Merge-deep project merge-deep prototype pollution vulnerabilityThe merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These …EPSS 1.9%9.8CVE-2021-33574Gnu glibc use after free vulnerabilityThe mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes ob…EPSS 2.9%

Source: NIST National Vulnerability Database (record CVE-2021-28164), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.