Amazon Linux 2 : jetty (ALAS-2024-2408)
Discription
It is, therefore, affected by a vulnerability as referenced in the ALAS2-2024-2408 advisory. For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to /concat?/%2557EB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application. (CVE-2021-28169) Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version…Read More
References
Back to Main