Vulnerability record · CVE-2021-34429 · published 15 July 2021
CVE-2021-34429: Eclipse Jetty URI encoding flaw exposes WEB-INF and bypasses security constraints
Eclipse · Jetty
Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 and 11.0.1-11.0.5 mishandle certain encoded characters in URIs, allowing crafted requests to reach the WEB-INF directory or bypass security constraints. It is a variant of CVE-2021-28164 and matters because it undermines the access controls applications rely on to protect sensitive files and restricted paths.
Description
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Automated analysis
high priorityVery high EPSS and a vendor advisory tagged Exploit make active exploitation likely, though the CVSS impact is limited to low confidentiality loss.
What it is
Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 and 11.0.1-11.0.5 mishandle certain encoded characters in URIs, allowing crafted requests to reach the WEB-INF directory or bypass security constraints. It is a variant of CVE-2021-28164 and matters because it undermines the access controls applications rely on to protect sensitive files and restricted paths.
Impact
An unauthenticated remote attacker can read content under WEB-INF, which typically holds configuration, class files and other sensitive material, and can reach resources that security constraints were meant to block. The CVSS vector limits the stated impact to low confidentiality loss with no integrity or availability effect.
Attack surface
Reachable over the network via HTTP requests to a Jetty-hosted application; the CVSS vector shows no privileges required and no user interaction. Any exposed Jetty instance in the affected version ranges is a candidate.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is very high (0.99298, 99.9th percentile) and the vendor advisory is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Eclipse Jetty to a release after 9.4.42, 10.0.5 or 11.0.5 as applicable; patch first.
- If immediate upgrade is not possible, restrict network access to Jetty services and place them behind a proxy that normalizes and rejects suspicious encoded URI paths.
- Audit deployed products that embed Jetty (NetApp and Oracle listings) and apply their corresponding vendor fixes.
- Review and tighten security constraint configuration so WEB-INF and protected paths are not reachable through alternate encodings.
Detection
- Monitor web access logs for requests containing encoded characters or traversal-like sequences targeting /WEB-INF/ or protected paths.
- Alert on HTTP requests with unusual percent-encoding or double-encoding in the URI path that reach normally restricted resources.
- Correlate Jetty server versions in inventory against the affected ranges to find unpatched instances.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-34429 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-34429), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.