Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-28169 — AI Deep Analysis Summary

CVSS 5.3 · Medium

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: Eclipse Jetty allows attackers to bypass security restrictions via **double URL encoding** in `ConcatServlet` requests.…

Q2Root Cause? (CWE/Flaw)

🛡️ **Root Cause**: **CWE-200** (Information Exposure). The flaw lies in how Jetty handles **doubly encoded paths**, failing to properly restrict access to internal directories like `WEB-INF`.

Q3Who is affected? (Versions/Components)

📦 **Affected Versions**: • Jetty **9.4.40** and earlier • Jetty **10.0.2** and earlier • Jetty **11.0.2** and earlier 🏢 **Vendor**: The Eclipse Foundation.

Q4What can hackers do? (Privileges/Data)

💀 **Attacker Capabilities**: • Access sensitive files in `WEB-INF`. • **Modify data**. • Execute **unauthorized administrative operations**. • Gain context of the affected site.

Q5Is exploitation threshold high? (Auth/Config)

⚡ **Exploitation Threshold**: **LOW**. • **Auth**: None required (PR:N). • **Network**: Remote (AV:N). • **UI**: No interaction needed (UI:N). • **Complexity**: Low (AC:L).

Q6Is there a public Exp? (PoC/Wild Exploitation)

🔓 **Public Exploits**: **YES**. • PoCs available on GitHub (ProjectDiscovery, Vulhub). • Widely documented in mailing lists (Kafka, Debian LTS). • Easy to reproduce with standard tools.

Q7How to self-check? (Features/Scanning)

🔍 **Self-Check**: • Scan for **Jetty** servers. • Check version numbers against the affected list. • Use Nuclei templates (`CVE-2021-28169.yaml`) for automated detection. • Look for `ConcatServlet` endpoints.

Q8Is it fixed officially? (Patch/Mitigation)

✅ **Official Fix**: **YES**. • Upgrade to **Jetty 9.4.41+**. • Upgrade to **Jetty 10.0.3+**. • Upgrade to **Jetty 11.0.3+**. • Patches are available via official Eclipse channels.

Q9What if no patch? (Workaround)

🚧 **No Patch Workaround**: • **Block** access to `ConcatServlet` via WAF/Reverse Proxy. • **Restrict** access to `WEB-INF` directories at the server level. • **Disable** unnecessary servlets if not used.

Q10Is it urgent? (Priority Suggestion)

🔥 **Urgency**: **HIGH**. • CVSS Score: **5.3** (Medium), but **Remote/No Auth** makes it critical for exposed services. • Many major projects (Kafka, Zookeeper) were impacted.…